CVE-2025-2611
CRITICAL EXPLOITED NUCLEIICTBroadcast - Command Injection
Title source: nucleiDescription
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.
Exploits (1)
metasploit
WORKING POC
EXCELLENT
by Valentin Lobstein · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ictbroadcast_unauth_cookie.rb
Nuclei Templates (1)
ICTBroadcast - Command Injection
CRITICALVERIFIEDby Chocapikk
Shodan:
html:"ICTBroadcast"
Scores
CVSS v4
9.3
EPSS
0.7277
EPSS Percentile
98.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H
Details
VulnCheck KEV
2025-10-12
CWE
CWE-78
Status
published
Products (1)
ICT Innovations/ICTBroadcast
< 7.4
Published
Aug 05, 2025
Tracked Since
Feb 18, 2026