External risk intelligence

Zenitel TCIV-3+ Reflected Cross-Site Scripting Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2025-64130

The Zenitel TCIV-3+ is an intercom station often deployed in environments where web-based management or user interfaces may be accessible over a network. As a network-connected communication device, it is commonly exposed as an edge service or appliance interface, making it a likely target for network-based interaction.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Zenitel TCIV-3+ devices that could allow a remote attacker to execute malicious JavaScript within a user's browser. This type of vulnerability can often lead to unauthorized actions or information disclosure. The main concern is confirming if this technology is deployed within your environment.

  • Attackers can run custom code via web browsers.
  • Matters if network devices are directly managed.
  • Confirm device presence and network exposure.

Attack Path

How an attacker could exploit the issue

An attacker could potentially reach a vulnerable component in the Zenitel TCIV-3+ by interacting with it over a network. This interaction could lead to the execution of arbitrary JavaScript within a victim's browser, as the device appears to be a network-accessible communication station.

  • Entry Condition: Network access is required.
  • Trigger Point: Interaction with the vulnerable component.
  • Resulting Risk: Arbitrary JavaScript execution on victim browsers.

Live Threat

Current exploitation, exposure, and threat context

A remote attacker could inject malicious JavaScript into a user's browser by exploiting a reflected cross-site scripting vulnerability in the Zenitel TCIV-3+. This could lead to the execution of arbitrary JavaScript code within the context of the victim's session when interacting with the affected device.

  • Arbitrary JavaScript execution on user browsers.
  • Crafted web requests could trigger the vulnerability.
  • Compromised user sessions and potential further attacks.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Zenitel TCIV-3+ intercom devices, often managed via web interfaces, are likely owned by the infrastructure or platform teams responsible for operational technology. The immediate priority is to identify all deployed instances, determine their network exposure and criticality, and then confirm the specific owner before planning remediation.

  • Identify all deployed devices and their owners.
  • Verify network exposure and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Zenitel TCIV-3+?

The Zenitel TCIV-3+ is a network-connected intercom station designed for secure, high-quality audio communication in industrial and commercial settings. It functions as an edge device that users typically manage through an integrated web interface, allowing for configuration and control over the network.

What does CVE-2025-64130 mean?

This CVE represents a reflected cross-site scripting (XSS) weakness, classified as CWE-79. It occurs when a web application improperly handles user input, allowing an attacker to inject and execute malicious JavaScript code. When a user interacts with a specially crafted link, that script runs within their own browser session, potentially leading to unauthorized actions.

How is the vulnerability triggered?

An attacker triggers this bug by sending a crafted web request to the intercom device. It requires network access to the device's interface. It is important to note that simply having the device powered on or connected to a network is not enough; the vulnerability is only activated when a user interacts with malicious content designed to exploit the input flaw.

Do I need to worry about this device?

If you manage Zenitel TCIV-3+ units, you should evaluate your risk. Halo Surface Signal identifies this device as a likely target because these intercoms are frequently deployed as network-accessible edge services. If your devices are reachable from the broader network rather than being strictly isolated, they are more susceptible to this remote interaction.

When should I take action?

You should begin by locating all deployed TCIV-3+ units in your environment to understand their current reach and role. After identifying these assets, coordinate with your infrastructure or platform teams to verify their network exposure. Prioritize these actions to determine the business criticality of the affected devices before planning further security measures.

References