2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation.
This vulnerability can only be exploited after authenticating with administrator privileges.
References
| Link | Resource |
|---|---|
| https://www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-04 16:16
Updated : 2026-03-05 15:02
NVD link : CVE-2025-59784
Mitre link : CVE-2025-59784
CVE.ORG link : CVE-2025-59784
JSON object : View
Products Affected
2n
- access_commander
CWE
CWE-117
Improper Output Neutralization for Logs
