CVE-2025-3362
CRITICALCVSS 9.8/10EPSS 1.32%
Last modified
CVE-2025-3362 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.. EPSS estimates a 1.32% chance of exploitation in the next 30 days.
Description
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-3362?
The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
How severe is CVE-2025-3362?
CVE-2025-3362 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.32% probability of exploitation in the next 30 days.
How do I fix CVE-2025-3362?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-3356IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 2…9.8
- CVE-2025-3357IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 1…9.8
- CVE-2025-3358Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-3359A flaw was found in GNUPlot. A segmentation fault via IO_str…6.2
- CVE-2025-3360A flaw was found in GLib. An integer overflow and buffer und…3.7
- CVE-2025-3361The web service of iSherlock from HGiga has an OS Command In…9.8
- CVE-2025-3363The web service of iSherlock from HGiga has an OS Command In…9.8
- CVE-2025-3364The SSH service of PowerStation from HGiga has a Chroot Esca…6.7
- CVE-2025-3365A missing protection against path traversal allows to access…9.8
- CVE-2025-3369A vulnerability was found in xxyopen Novel-Plus 5.1.0. It ha…9.8
- CVE-2025-3370A vulnerability classified as critical has been found in PHP…9.8
- CVE-2025-3371A vulnerability, which was classified as critical, has been …9.8
Are you affected by CVE-2025-3362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
