A critical security vulnerability has been identified in the MegaSys Enterprises Telenium Online Web Application, allowing unauthenticated attackers to execute arbitrary operating system commands on affected servers. The flaw, tracked as CVE-2025-10659, arises from improper input handling in a PHP endpoint that is accessible over the network without authentication. Specifically, the vulnerability is due to insecure termination of a regular expression check, which fails to adequately validate or sanitize user-supplied input. As a result, attackers can craft malicious HTTP requests that inject OS commands, leading to remote code execution within the security context of the web application service account. The vulnerability affects Telenium Online Web Application versions 8.4.21 and prior, as confirmed by both CVE and CISA advisories. The issue is classified as an OS command injection (CWE-78), a category of vulnerabilities known for their high impact and ease of exploitation. The CVSS v3.1 base score for this vulnerability is 9.8, indicating a critical risk, while a CVSS v4 score of 9.3 further underscores its severity. The vulnerability is remotely exploitable and requires no user interaction or authentication, making it particularly dangerous for internet-exposed systems. Successful exploitation could allow attackers to gain control over the affected server, potentially leading to data theft, service disruption, or lateral movement within the network. The vulnerability was disclosed by ics-cert@hq.dhs.gov and has been publicly documented in both CVE and CISA ICS advisories. Organizations using the Telenium Online Web Application are strongly advised to review their deployments and apply any available patches or mitigations. The advisories do not specify the exact versions affected beyond 8.4.21 and prior, so all users of the product should consider themselves at risk until further information is available. No reports of exploitation in the wild have been confirmed at the time of the advisories' publication, but the low attack complexity and high impact make rapid remediation essential. The vulnerability highlights the ongoing risks associated with improper input validation in web applications, especially those used in industrial control system environments. Security teams should prioritize network segmentation and monitoring for unusual HTTP request patterns targeting the vulnerable endpoint. The incident serves as a reminder of the importance of secure coding practices and regular security assessments for critical infrastructure software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CISA published ICS Advisory ICSA-25-273-01 warning of CVE-2025-10659, a critical unauthenticated OS command injection vulnerability in MegaSys Enterprises Telenium Online Web Application. CISA said the issue had no known public exploitation at the time of publication.
MegaSys Enterprises provided a fix for an OS command injection vulnerability in the Telenium Online Web Application and directed customers to its support resources for remediation. The flaw affects version 8.4.21 and earlier and can allow remote code execution via a crafted HTTP request.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.