CVE-2019-25468

CRITICAL

NetGain EM Plus 10.1.68 - Unauthenticated Remote Code Execution via script_test.jsp Content Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25468. PoCs published by azams.

AI-analyzed exploit summary This Go-based exploit targets a local file inclusion vulnerability in NetGain EM Plus <= v10.1.68, allowing unauthorized command execution via a crafted POST request to '/u/jsp/designer/script_test.jsp'. The exploit sends a shell command wrapped in markers ('0xdeadnoob') to extract the output.

Description

NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in the 'content' parameter to execute code and retrieve command output.

Exploits (1)

exploitdb WORKING POC
by azams · gowebappsjsp
https://www.exploit-db.com/exploits/47391

This Go-based exploit targets a local file inclusion vulnerability in NetGain EM Plus <= v10.1.68, allowing unauthorized command execution via a crafted POST request to '/u/jsp/designer/script_test.jsp'. The exploit sends a shell command wrapped in markers ('0xdeadnoob') to extract the output.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: NetGain EM Plus <= v10.1.68
No auth needed
Prerequisites: network access to target · target service running on specified port
devstral-2 · analyzed Mar 12, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47391
Various Sources product
http://netgain-systems.com

Scores

CVSS v3 9.8
EPSS 0.0033
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
NetGain Systems/NetGain EM Plus 10.1.68
Published Mar 11, 2026
Tracked Since Mar 12, 2026