CVE-2020-25850: Hgiga MSR45 Isherlock-User

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

The function, view the source code, of HGiga MailSherlock does not validate specific characters. Remote attackers can use this flaw to download arbitrary system files.

Affected products

  • Hgiga MSR45 Isherlock-User: before 4.5-117 (fixed in 4.5-117)
  • Hgiga SSR45 Isherlock-User: before 4.5-117 (fixed in 4.5-117)

Published 2020-12-31. Last modified 2026-06-17.