Vulnerability record · CVE-2026-25108 · published 13 February 2026
CVE-2026-25108: FileZen OS command injection via Antivirus Check Option
Soliton · Filezen
FileZen contains an OS command injection flaw (CWE-78) that is reachable when the Antivirus Check Option is enabled. A logged-in user can send a specially crafted HTTP request to execute arbitrary OS commands on the host. Because it allows command execution with high impact to confidentiality, integrity and availability, it is a serious risk to any exposed FileZen deployment.
Description
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityThe flaw allows authenticated remote OS command execution with high impact and is listed in CISA KEV as actively exploited.
What it is
FileZen contains an OS command injection flaw (CWE-78) that is reachable when the Antivirus Check Option is enabled. A logged-in user can send a specially crafted HTTP request to execute arbitrary OS commands on the host. Because it allows command execution with high impact to confidentiality, integrity and availability, it is a serious risk to any exposed FileZen deployment.
Impact
An attacker with a valid low-privileged account gains arbitrary OS command execution on the FileZen server, enabling data theft, tampering, or full host compromise. The CVSS 4.0 vector shows high impact to confidentiality, integrity and availability of the vulnerable system.
Attack surface
Reached over the network via a crafted HTTP request (AV:N, AC:L) and requires the attacker to be logged in (PR:L) with no user interaction (UI:N). The vulnerable code path is only active when the FileZen Antivirus Check Option is enabled.
Exploitation
CVE-2026-25108 is listed in CISA's Known Exploited Vulnerabilities catalog with a remediation due date of 2026-03-17, indicating active exploitation. EPSS gives a 30-day probability of about 5.1 percent (91.9th percentile); no ransomware campaign use is documented.
What to do
- Apply the vendor fix per the Soliton advisory (https://www.soliton.co.jp/support/2026/006657.html) as the first action.
- If no patch is available, disable the FileZen Antivirus Check Option or discontinue use of the product, per CISA's required action.
- Restrict network access to FileZen management and upload interfaces to trusted networks and limit accounts to only those that need them.
- Audit and remove unnecessary user accounts, and monitor for anomalous command execution or child processes spawned by the FileZen service.
- Follow BOD 22-01 guidance for any cloud-hosted FileZen instances.
Detection
- Search FileZen HTTP request logs for crafted or anomalous requests targeting the antivirus check functionality.
- Monitor for unexpected child processes or shell commands spawned by the FileZen service account.
- Alert on outbound connections or file writes from the FileZen host that deviate from normal behavior.
- Correlate FileZen authentication events with subsequent process creation to spot post-login command execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-25108 to the Known Exploited Vulnerabilities catalog on 24 February 2026 as "Soliton Systems K.K FileZen OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 17 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN84622767/ | Third Party Advisory |
| https://www.soliton.co.jp/support/2026/006657.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25108 | US Government Resource |
Track CVE-2026-25108 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-25108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.