PoC Index

CVE-2025-9176

HIGH 7.8EPSS 1.3%

A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local access. The exploit has been released to the public and may be exploited. Es wurde eine Schwachstelle in neurobin shc bis 4.0.3 entdeckt. Dabei geht es um die Funktion make der Datei src/shc.c der Komponente Environment Variable Handler. Die Bearbeitung verursacht os command injection. Der Angriff muss lokal passieren. Die Schwachstelle wurde öffentlich offengelegt und könnte ausgenutzt werden.

CVSS v4.0
1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS v2.0
4.3 MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.29% chance of exploitation in the next 30 days, 68th percentile
Published
2025-08-19
Updated
2025-08-20

Proof-of-concept exploits (1)

References

Related