CVE-2025-11900: Hgiga Isherlock 4.5

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

Affected products

  • Hgiga Isherlock 4.5: before 774 (fixed in 774); before 440 (fixed in 440)
  • Hgiga Isherlock 5.5: before 774 (fixed in 774); before 440 (fixed in 440)

Published 2025-10-17. Last modified 2026-06-17.