MEDIUM
neurobin shc Environment Variable shc.c make os command injection
Published Aug 19, 2025
4.8
MEDIUMCVSS 4.0
EPSS 1.17%
Description
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
Affected products
-
- Version 4.0.0StatusaffectedConstraints-
- Version 4.0.1StatusaffectedConstraints-
- Version 4.0.2StatusaffectedConstraints-
- Version 4.0.3StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25253 Advisory
- https://magnificent-dill-351.notion.site/Command-Execution-of-env-in-shc-4-0-3-249c693918ed80c997f4e9420f945d01 exploitBroken Link
- https://vuldb.com/?ctiid.320557 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.320557 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.630744 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25253 | Advisory | |
| https://magnificent-dill-351.notion.site/Command-Execution-of-env-in-shc-4-0-3-249c693918ed80c997f4e9420f945d01 | exploitBroken Link | |
| https://vuldb.com/?ctiid.320557 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.320557 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.630744 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 19, 2025
Updated Aug 20, 2025
Reserved Aug 19, 2025
Link CVE-2025-9176
CISA Vulnrichment
Updated Aug 20, 2025
ENISA EUVD
EUVD-2025-25253 Assigner VulDB
Published Aug 19, 2025
Updated Aug 20, 2025
Exploited since n/a
Link EUVD-2025-25253