peter bassill · operator
$ cve CVE-2025-47228 JSON

CVE-2025-47228 EXPLOIT

6.7
MEDIUM · CVSS 3.1 · EPSS 17.5% (pctl 97)

Patch early

A public exploit exists.

Description

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows authenticated attackers to execute system commands via crafted HTTP requests.

Scoring

CVSS6.7 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
EPSS17.51% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2025-07-05
Last modified2026-06-17

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD