CVE-2025-3361
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-3361 is a newly discovered vulnerability affecting the web service of iSherlock from HGiga. This issue grants unauthenticated remote attackers the ability to inject and execute arbitrary OS commands on the server through an OS Command Injection weakness. Successful exploitation could result in significant data loss or unauthorized system access, making it an urgent security concern for users of this product. The vulnerability poses a serious threat, particularly for those with the iSherlock web service installed, as it may allow attackers to gain control of the underlying operating system. Organizations are advised to apply patches or updates as soon as they become available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Hgiga Isherlock
Affected Vendors
- HGiga Huanji Technology Co., Ltd.