CVE-2025-2611
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.
- Published Aug 5, 2025
- CVSS 9.3 critical
- 8.1% chance of exploitation in the next 30 days (EPSS)
- A Metasploit module exploits it
Affected software
In the news
- Frost Checks First: Selective Exploitation VulnCheck Blog ·
- The Mystery OAST Host Behind a Regionally Focused Exploit Operation VulnCheck Blog ·
- Introducing VulnCheck Canary Intelligence VulnCheck Blog ·
- VulnCheck Research Highlights: November 2025 VulnCheck Blog ·
- ICTBroadcast Command Injection Actively Exploited (CVE-2025-2611) VulnCheck Blog ·