
2N Access Commander 3.4.1-3.4.2 affected by two API flaws: CVE-2025-59783 enables OS command injection and CVE-2025-59785 weakens backup encryption, both require admin authentication. https://threatcluster.io/cluster/critical-vulnerabilities-found-in-2n-access-commander-api-2848adf9
Post summary
The post discloses two API flaws in 2N Access Commander—CVE‑2025‑59783 allows OS command injection, and CVE‑2025‑59785 weakens backup encryption—both requiring admin credentials, with no mention of exploitation or patching.



