CVE-2025-22905

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 94

Summary

CVE-2025-22905 is a newly disclosed vulnerability affecting RE11S v1.11. The issue involves a command injection vulnerability found in the /goform/mp endpoint. Malicious actors can exploit this flaw by injecting malicious commands into the command parameter, potentially gaining unauthorized access or executing arbitrary code on the affected system. This vulnerability poses a significant risk to the security of RE11S installations running version 1.11 and requires immediate attention from system administrators to apply available patches or workarounds.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share