# CVE-2025-59784

## Summary

- **CVE ID:** CVE-2025-59784
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-117
- **Published:** Mar 4, 2026
- **Last Modified:** Mar 13, 2026

## Description

2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation.
This vulnerability can only be exploited after authenticating with administrator privileges.

## Affected Products

- 2N Telekomunikace a.s. — 2N Access Commander (0)

## References

- [CNA](https://www.2n.com/en-GB/download/cve_2025_59784_acom_3_5_v1pdf)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 20.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._