CVE-2025-2611

CRITICAL EXPLOITED NUCLEI

ICTBroadcast - Command Injection

Title source: nuclei

Description

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Valentin Lobstein · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ictbroadcast_unauth_cookie.rb

Nuclei Templates (1)

ICTBroadcast - Command Injection
CRITICALVERIFIEDby Chocapikk
Shodan: html:"ICTBroadcast"

Scores

CVSS v4 9.3
EPSS 0.7277
EPSS Percentile 98.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H

Details

VulnCheck KEV 2025-10-12
CWE
CWE-78
Status published
Products (1)
ICT Innovations/ICTBroadcast < 7.4
Published Aug 05, 2025
Tracked Since Feb 18, 2026