CVE-2025-7451: Hgiga Isherlock-Maillog-4.5
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.
Affected products
- Hgiga Isherlock-Maillog-4.5: before 137 (fixed in 137)
- Hgiga Isherlock-Maillog-5.5: before 137 (fixed in 137)
- Hgiga Isherlock-Smtp-4.5: before 732 (fixed in 732)
- Hgiga Isherlock-Smtp-5.5: before 732 (fixed in 732)
Published 2025-07-14. Last modified 2026-06-17.