Zenitel VSF-Turbine, Fortitude6, Fortitude8, and ZIPS Authenticated Remote Code Execution Vulnerability via Uploaded Files

Vulnerability

A vulnerability exists in Zenitel's VSF-Turbine, Fortitude6, Fortitude8, and ZIPS products, allowing authenticated attackers to execute arbitrary commands on the underlying system by manipulating the file name of an uploaded file. This issue affects several different versions and ranges of the respective products.

Impact

Exploitation of this vulnerability could lead to unauthorized command execution on the affected system, potentially allowing for further exploitation or manipulation of the device.

Remediation

Users can upgrade to Zenitel's VSF-Turbine, Fortitude6, Fortitude8, or ZIPS versions 9.3.3.1 or later (8.2.3.5 for legacy TCIV) to address this vulnerability.

Added: Feb 4, 2026, 11:27 AM
Updated: Feb 4, 2026, 5:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
0.0
relevance
2.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.