2
N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation. This vulnerability can only be exploited after authenticating with administrator privileges.
References
| Link | Resource |
|---|---|
| https://www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf | Vendor Advisory |
Configurations
History
05 Mar 2026, 15:02
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
2n access Commander
2n |
|
| CPE | cpe:2.3:a:2n:access_commander:*:*:*:*:*:*:*:* | |
| References | () https://www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
04 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-04 16:16
Updated : 2026-03-05 15:02
NVD link : CVE-2025-59784
Mitre link : CVE-2025-59784
CVE.ORG link : CVE-2025-59784
JSON object : View
Products Affected
CWE
CWE-117
Improper Output Neutralization for Logs