PT-2025-42578 · Isherlock · Isherlock

Published

2025-10-17

·

Updated

2025-10-22

·

CVE-2025-11900

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HGiga iSherlock version 4.5
Description The iSherlock software contains an OS Command Injection flaw. This allows unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. Successful exploitation could lead to full system compromise. The vulnerability grants immediate root-level server access without requiring credentials.
Recommendations Restrict access to the iSherlock software version 4.5. Monitor the system for suspicious activity. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11900

Affected Products

Isherlock