← Vulnerability feed

Vulnerability record · CVE-2025-59787 · published 4 March 2026

CVE-2025-59787: 2n access commander vulnerability

22n · Access Commander

2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving malformed or manipulated requests, indicating improper handling of invalid input and potential security or availability impacts.

5.3 CVSS 4.0 Medium EPSS 0.19% · top 92.2% CWE-703 · CWE-703
5.3CVSS 4.0 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

2N Access Commander application version 3.4.2 and prior returns HTTP 500 Internal Server Error responses when receiving malformed or manipulated requests, indicating improper handling of invalid input and potential security or availability impacts.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59787 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-597832n access commander os command injection vulnerabilityAPI endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injecti…EPSS 0.86%7.8CVE-2024-472552n access commander vulnerabilityIn 2N Access Commander versions 3.1.1.2 and prior, a local attacker can escalate their privileges in the system which could allow for arbitrary code …EPSS 0.10%7.2CVE-2024-472542n access commander vulnerabilityIn 2N Access Commander versions 3.1.1.2 and prior, an Insufficient Verification of Data Authenticity vulnerability could allow an attacker to escalat…EPSS 0.35%7.2CVE-2024-472532n access commander path traversal vulnerabilityIn 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write fil…EPSS 0.95%6.9CVE-2025-597842n access commander vulnerability2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prio…EPSS 0.29%6.0CVE-2025-597862n access commander insufficient session expiration vulnerability2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in…EPSS 0.25%5.3CVE-2025-597852n access commander vulnerabilityImproper validation of API end-point in 2N Access Commander version 3.4.2 and prior allows attacker to bypass password policy for backup file encrypt…EPSS 0.19%7.8CVE-2022-22265Samsung NPU driver improper exception handling enables memory write and code executionThe NPU driver in Samsung Android devices mishandles exceptional conditions, allowing arbitrary memory writes and code execution. The flaw was fixed …KEVEPSS 0.39%analysed

Source: NIST National Vulnerability Database (record CVE-2025-59787), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.