CVE-2025-10020High· 8.5▾ TwilightZohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.8 · likelihood 0.9 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.5%
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
manageengine_admanager_plus < 8.0manageengine_admanager_plus = 8.0Upgrade past the affected range:
manageengine_admanager_plus 8.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-11670Medium· 6.4Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
CVE-2025-12313Medium· 6.3A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1
CVE-2025-13562High· 7.3A vulnerability was identified in D-Link DIR-852 1.00
CVE-2025-14225Medium· 6.3A vulnerability was determined in D-Link DCS-930L 1.15.04
CVE-2025-14707Critical· 9.8A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14706Critical· 9.8A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25