PT-2025-31937 · Unknown · Ictbroadcast

Valentin Lobstein

·

Published

2025-03-19

·

Updated

2025-12-10

·

CVE-2025-2611

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ICTBroadcast versions 7.4 and below
Description The ICTBroadcast application improperly handles session cookie data, passing it to shell processing. This allows an attacker to inject shell commands into a session cookie, leading to unauthenticated remote code execution on the server. Approximately 200 servers are reported as exposed, and the issue is currently being actively exploited in the wild. The vulnerability is triggered by manipulating the BROADCAST session cookie. The application does not adequately validate input, allowing for command injection.
Recommendations Versions prior to 7.4 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14633
CVE-2025-2611

Affected Products

Ictbroadcast