PoC Index

CVE-2025-4428

KEVHIGH 8.8EPSS 86.2%

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
86.19% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2025-05-19
Published
2025-05-13
Updated
2026-02-26

Proof-of-concept exploits (4)

Metasploit modules (1)

References

Related