CVE-2025-22905
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 94
Summary
CVE-2025-22905 is a newly disclosed vulnerability affecting RE11S v1.11. The issue involves a command injection vulnerability found in the /goform/mp endpoint. Malicious actors can exploit this flaw by injecting malicious commands into the command parameter, potentially gaining unauthorized access or executing arbitrary code on the affected system. This vulnerability poses a significant risk to the security of RE11S installations running version 1.11 and requires immediate attention from system administrators to apply available patches or workarounds.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.