Record summary

CVE-2025-34079 has a selected CVSS score of 7.5 (high); EIP currently links 2 catalogued exploits.

Description

An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and ExternalScripts module are enabled. A remote attacker with the administrator password can authenticate to the web interface (default port 8443), inject arbitrary commands as external scripts via the /settings/query.json API, save the configuration, and trigger the script via the /query/{name} endpoint. The injected commands are executed with SYSTEM privileges, enabling full remote compromise. This capability is an intended feature, but the lack of safeguards or privilege separation makes it risky when exposed to untrusted actors.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 2, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List0.5.2.35affected

Proofs of concept

2

Catalogued exploits

ExploitDBNSClient++ 0.5.2.35 - Authenticated Remote Code ExecutionExploitDB exploitby kindredsecNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details
MetasploitNSClient++ 0.5.2.35 - ExternalScripts Authenticated Remote Code ExecutionMetasploit exploitby Yann Castel (yann.castel <Yann Castel (yann.castel@orange.com)> +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

4