CVE-2025-3362: Hgiga Isherlock 4.5

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

Affected products

  • Hgiga Isherlock 4.5: before 236 (fixed in 236)
  • Hgiga Isherlock 5.5: before 236 (fixed in 236)

Published 2025-04-08. Last modified 2026-06-17.