PT-2025-31937 · Unknown · Ictbroadcast

Valentin Lobstein

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-2611

CVSS v4.0
9.3
VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H

Name of the Vulnerable Software and Affected Versions:

ICTBroadcast versions 7.4 and below

Description:

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling.

Recommendations:

Update ICTBroadcast to a version later than 7.4.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-2611

Affected Products

Ictbroadcast