nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-7451 CVE-2025-7451
CRITICAL
Hgiga|iSherlock - OS Command Injection
Record summary
CVE-2025-7451 has a selected CVSS score of 9.3 (critical).
Description
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 11, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 14, 2025 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
iSherlockBrowse Hgiga / iSherlock | VulnCheck | Version data not supplied | |
iSherlock-maillog-4.5Browse Hgiga / iSherlock-maillog-4.5Default status: unaffected | CVE List | Before 137 | affected |
iSherlock-maillog-5.5Browse Hgiga / iSherlock-maillog-5.5Default status: unaffected | CVE List | Before 137 | affected |
iSherlock-smtp-4.5Browse Hgiga / iSherlock-smtp-4.5Default status: unaffected | CVE List | Before 732 | affected |
iSherlock-smtp-5.5Browse Hgiga / iSherlock-smtp-5.5Default status: unaffected | CVE List | Before 732 | affected |
References
3twcert.org.twThird-party advisory
https://www.twcert.org.tw/en/cp-139-10238-f2bba-2.html twcert.org.twThird-party advisory
https://www.twcert.org.tw/tw/cp-132-10237-9e0f7-1.html