CVE-2019-25468
CRITICALNetGain EM Plus 10.1.68 - RCE
Title source: llmDescription
NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in the 'content' parameter to execute code and retrieve command output.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0031
EPSS Percentile
54.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (1)
NetGain Systems/NetGain EM Plus
10.1.68
Published
Mar 11, 2026
Tracked Since
Mar 12, 2026