// For flags

CVE-2025-34082

IGEL OS Secure Terminal and Secure Shadow Remote Code Execution

Severity Score

9.3
*CVSS v4

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Shadow services. The flaw arises due to improper input sanitization in the handling of specially crafted PROXYCMD commands on TCP ports 30022 and 5900. An unauthenticated attacker with network access to a vulnerable device can inject arbitrary commands, leading to remote code execution with elevated privileges. NOTE: IGEL OS v10.x has reached end-of-life (EOL) status.

Existe una vulnerabilidad de inyección de comandos en versiones de IGEL OS anteriores a la 11.04.270 dentro de los servicios Secure Terminal y Secure Shadow. La falla surge debido a una depuración de entrada incorrecta al gestionar comandos PROXYCMD especialmente manipulados en los puertos TCP 30022 y 5900. Un atacante no autenticado con acceso de red a un dispositivo vulnerable puede inyectar comandos arbitrarios, lo que provoca la ejecución remota de código con privilegios elevados. NOTA: El sistema operativo IGEL v10.x ha alcanzado el fin de su ciclo de vida (EOL).

*Credits: Rob Vinson of NCC Group
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
System
Vulnerable | Subsequent
Confidentiality
High
None
Integrity
High
None
Availability
High
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2025-04-15 CVE Reserved
  • 2025-07-03 CVE Published
  • 2025-07-03 CVE Updated
  • 2025-07-03 First Exploit
  • 2025-07-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
  • CAPEC-88: OS Command Injection
  • CAPEC-137: Parameter Injection
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
IGEL Technology GmbH
Search vendor "IGEL Technology GmbH"
OS
Search vendor "IGEL Technology GmbH" for product "OS"
>= 11.0.0 < 11.04.270
Search vendor "IGEL Technology GmbH" for product "OS" and version " >= 11.0.0 < 11.04.270"
en
Affected
IGEL Technology GmbH
Search vendor "IGEL Technology GmbH"
OS
Search vendor "IGEL Technology GmbH" for product "OS"
>= 10.0.0 < 10.06.220
Search vendor "IGEL Technology GmbH" for product "OS" and version " >= 10.0.0 < 10.06.220"
en
Affected