CVE-2025-7451: Hgiga|iSherlock - OS Command Injection
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iSherlock-maillogto a version that resolves this vulnerability.Fixed in 137 - Upgrade
Upgrade
iSherlock-smtpto a version that resolves this vulnerability.Fixed in 732
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7451?
CVE-2025-7451 is considered a critical vulnerability due to its potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2025-7451?
To fix CVE-2025-7451, you should update to the latest version of the Hgiga iSherlock software that includes the security patch.
What types of systems are affected by CVE-2025-7451?
CVE-2025-7451 affects the Hgiga iSherlock software, allowing for command injection vulnerabilities.
Can CVE-2025-7451 be exploited remotely?
Yes, CVE-2025-7451 can be exploited remotely by unauthorized attackers to execute arbitrary OS commands.
Has CVE-2025-7451 been actively exploited?
Yes, CVE-2025-7451 has already been reported as actively exploited in the wild.