Description

The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject shell commands into a session cookie that get executed on the server. This results in unauthenticated remote code execution in the session handling. Versions 7.4 and below are known to be vulnerable.

INFO

Published Date :

2025-08-05T15:00:32.531Z

Last Modified :

2025-11-04T22:19:15.078Z

Source :

VulnCheck
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2611 vulnerability.

Vendors Products
Ict Innovations
  • Ictbroadcast
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability