CVE-2025-2611 PUBLISHED

ICTBroadcast Unauthenticated Session Cookie Remote Code Execution

Assigner: VulnCheck
Reserved: 21.03.2025 Published: 05.08.2025 Updated: 06.08.2025

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling.

Versions 7.4 and below are known to be vulnerable.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H
CVSS Score: 9.3

Product Status

Vendor ICT Innovations
Product ICTBroadcast
Versions Default: unknown
  • affected from 0 to 7.4 (incl.)

Credits

  • Valentin Lobstein (Chocapikk) finder

References

Problem Types

  • CWE-20 Improper Input Validation CWE

Impacts

  • CAPEC-88 OS Command Injection