CVE-2025-59785Disclosure(2n / access_commander)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnerability can only be exploited after authenticating with administrator privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1286

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • access_commander

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
access_commander

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-04: 4Mentions · 2026-03-05: 1Technical Details · 2026-03-04: 4Technical Details · 2026-03-05: 103-0403-05
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-044
Disclosure3General1
2026-03-051
Disclosure1
Full discourse5 posts
  • ThreatCluster@threatcluster
    Disclosure

    2N Access Commander 3.4.1-3.4.2 affected by two API flaws: CVE-2025-59783 enables OS command injection and CVE-2025-59785 weakens backup encryption, both require admin authentication. https://threatcluster.io/cluster/critical-vulnerabilities-found-in-2n-access-commander-api-2848adf9

    Post summary

    The post announces the discovery of two API flaws in 2N Access Commander (CVE‑2025‑59783, OS command injection; CVE‑2025‑59785, weakened backup encryption), both requiring admin authentication.

    0000080
    91 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-59785 Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnera… https://www.cve.org/CVERecord?id=CVE-2025-59785 ----- Traducción: CVE-2025-59785 Val… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-59785, details how improper API validation enables bypassing the backup encryption password policy, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000088
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59785 Improper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encryption. This vulnera… https://www.cve.org/CVERecord?id=CVE-2025-59785

    Post summary

    The tweet announces CVE‑2025‑59785, specifying that an API endpoint validation flaw in 2N Access Commander permits bypassing the backup file password policy, but reports no PoC, exploit, or active exploitation details.

    00000176
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-59785 2N Access Commander Authentication Bypass Vulnerability in API Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-59785

    Post summary

    A new authentication bypass vulnerability (CVE‑2025‑59785) has been disclosed for 2N Access Commander’s API endpoint, yet the brief post lacks any PoC, exploit, or patch information.

    0000076
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-59785 - API - Insufficient Input Validation Intel Report: https://ift.tt/AVasRbC

    Post summary

    Alert informs about CVE-2025-59785 as an API input validation issue, but provides no exploit evidence or patch information.

    0000096
    344 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App2naccess_commander---

Explore more