CVE-2025-7451 is a critical OS Command Injection vulnerability in Hgiga's iSherlock product, allowing unauthenticated remote attackers to execute arbitrary commands on the server. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Crucially, this vulnerability is already being actively exploited in the wild, as confirmed by community discussions and a high FAUCET Risk Score of 95/100. While no public exploit code is currently available on platforms like Metasploit or ExploitDB, the active exploitation necessitates immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Hgiga | ISherlock-Maillog-4.5 | >= 0, < 137CNA affecteddefault unaffected | |
| Hgiga | ISherlock-Maillog-5.5 | >= 0, < 137CNA affecteddefault unaffected | |
| Hgiga | ISherlock-Smtp-4.5 | >= 0, < 732CNA affecteddefault unaffected | |
| Hgiga | ISherlock-Smtp-5.5 | >= 0, < 732CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.