Record summary

CVE-2025-34082 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Shadow services. The flaw arises due to improper input sanitization in the handling of specially crafted PROXYCMD commands on TCP ports 30022 and 5900. An unauthenticated attacker with network access to a vulnerable device can inject arbitrary commands, leading to remote code execution with elevated privileges. NOTE: IGEL OS v10.x has reached end-of-life (EOL) status.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 7, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List11 to < 11.04.270affected
10 to < 10.06.220affected

Proofs of concept

1

Catalogued exploits

MetasploitIGEL OS Secure VNC/Terminal Command Injection RCEMetasploit exploitby James Brytan +5 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

5