CVE-2025-2611 Information
Aug 06, 2025
cve
Description
The ICTBroadcast application unsafely passes session cookie data to shell processing allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling.
Versions 7.4 and below are known to be vulnerable.
Reference
https://github.com/rapid7/metasploit-framework/pull/20446
Related CNNVD
CNNVD-202508-341 (Published: 2025-08-05)
Share on: