A critical security vulnerability, CVE-2025-2611, has been discovered in ICTBroadcast, an autodialer and call center software developed by ICT Innovations. This flaw, which scores 9.3 on the CVSS scale, arises from improper input validation that allows unauthenticated remote code execution through the BROADCAST session cookie. Attackers can inject shell commands into this cookie, which are then executed on the vulnerable server, granting them remote shell access. The vulnerability affects ICTBroadcast versions 7.4 and below, and approximately 200 instances are currently exposed to the internet, despite recommendations that such software should not be internet-facing. VulnCheck researchers observed active exploitation of this vulnerability beginning on October 11, 2025, with attacks occurring in two distinct phases. Initially, attackers use a time-based exploit check, such as a base64-encoded 'sleep 3' command, to confirm the ability to execute commands. Once confirmed, they proceed to establish reverse shells on the compromised systems. The attack payloads are delivered via specially crafted HTTP requests, leveraging the BROADCAST cookie to pass malicious commands. Some payloads have used a localto[.]net URL and the IP address 143.47.53[.]106, both of which have been previously associated with campaigns distributing the Ratty RAT malware in Europe, suggesting possible reuse of infrastructure or tooling. The vulnerability was originally discovered and reported to the vendor in March 2025 by security researcher Valentin Lobstein, who later published a Metasploit module after the vendor failed to address the issue within the 120-day disclosure window. VulnCheck has provided detection signatures for Snort and Suricata, as well as IP intelligence, to help organizations identify and mitigate exploitation attempts. There is currently no public information regarding the availability of a patch from ICT Innovations. The ongoing exploitation highlights the risk posed by internet-exposed call center software and the importance of timely vulnerability management. Security researchers emphasize the need for organizations to remove ICTBroadcast instances from public internet exposure and to monitor for signs of compromise. The overlap in indicators with previous malware campaigns raises concerns about broader threat actor activity and the potential for further attacks leveraging this vulnerability. Organizations using ICTBroadcast are urged to implement network segmentation, monitor for suspicious activity, and apply any available mitigations while awaiting an official patch. The incident underscores the criticality of secure software development practices and prompt vendor response to vulnerability disclosures.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
A CSIRT.SK advisory published on 2025-10-21 stated that CVE-2025-2611 in ICTBroadcast remained actively exploited and that no patch was available at the time. The advisory recommended restricting access to trusted IPs, validating BROADCAST cookie contents, and reviewing logs for listed indicators of compromise.
On 2025-10-15, a ProjectDiscovery Nuclei templates pull request added coverage for CVE-2025-2611 and included a Docker-based lab setup to reproduce the issue in a vulnerable ICTBroadcast environment. The submission also referenced related public exploit tooling and validation steps.
On 2025-10-14, VulnCheck published research describing CVE-2025-2611 as an actively exploited ICTBroadcast vulnerability affecting version 7.4 and below. The report documented a two-stage attack pattern involving a time-delay test and subsequent reverse-shell attempts.
VulnCheck reported that active exploitation of CVE-2025-2611 against ICTBroadcast servers began on 2025-10-11. The unauthenticated command injection flaw abuses the BROADCAST cookie to achieve remote code execution.
On 2025-05-08, Fortinet disclosed a high-severity phishing campaign using PDF invoice lures, Dropbox-hosted HTML, and Ngrok-based geo-fencing to deliver the Java-based Ratty RAT to targets in Spain, Italy, and Portugal. The report said the campaign abused the legitimate email service serviciodecorreo.es to pass SPF checks and published detection coverage and IOCs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcegithub.com
Open sourcethehackernews.com
Open sourcevulncheck.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.