VDB
CVE-2025-7451
CVE-2025-7451
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.
EPSS 1.39% · 71.4th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.39%
71.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hgiga | iSherlock-maillog-4.5 | 0, 0 |
| Hgiga | iSherlock-smtp-5.5 | 0, 0 |
| Hgiga | iSherlock-smtp-4.5 | 0, 0 |
| Hgiga | iSherlock-maillog-5.5 | 0, 0 |
Timeline
- Jul 11, 2025 VulnCheck KEV Exploitation
- Jul 14, 2025 EPSS Score
- Jul 14, 2025 CVE Published
- Jul 14, 2025 CVE Updated
- Jul 15, 2025 PoC Published
- Jul 24, 2025 EPSS Score
- Aug 3, 2025 EPSS Score
- Aug 13, 2025 EPSS Score
- Aug 22, 2025 EPSS Score
- Sep 1, 2025 EPSS Score
- Sep 11, 2025 EPSS Score
- Sep 21, 2025 EPSS Score
References
- https://www.twcert.org.tw/tw/cp-132-10237-9e0f7-1.html third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-7451 advisory
- https://www.twcert.org.tw/en/cp-139-10238-f2bba-2.html technical