CVE-2025-2611 Information

Description

The ICTBroadcast application unsafely passes session cookie data to shell processing allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling.

Versions 7.4 and below are known to be vulnerable.

Reference

https://github.com/rapid7/metasploit-framework/pull/20446

CNNVD-202508-341 (Published: 2025-08-05)

Share on: