OS Command Injection Vulnerability in iSherlock by HGiga
CVE-2025-11900

9.3CRITICAL

Key Information:

Vendor

Hgiga

Vendor
CVE Published:
17 October 2025

What is CVE-2025-11900?

The iSherlock application developed by HGiga is vulnerable to an OS Command Injection issue, enabling unauthenticated remote attackers to execute arbitrary operating system commands. This flaw can be exploited by sending specially crafted requests to the server, compromising its security and potentially leading to unauthorized access and control over the affected system. Users of iSherlock are urged to review their configurations and apply necessary security measures to mitigate this vulnerability.

Affected Version(s)

iSherlock 4.5 0 < 774

iSherlock 4.5 0 < 440

iSherlock 5.5 0 < 774

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11900 : OS Command Injection Vulnerability in iSherlock by HGiga