VYPR
Unrated severityNVD Advisory· Published Sep 22, 2021· Updated Aug 4, 2024

CVE-2021-37925

CVE-2021-37925

Description

Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Post-authentication OS command injection in Zoho ManageEngine ADManager Plus versions 7110 and prior allows authenticated users to execute arbitrary commands.

Vulnerability

Zoho ManageEngine ADManager Plus versions 7110 and prior contain a post-authentication OS command injection vulnerability. The vulnerability exists in an unspecified component that allows authenticated users to inject operating system commands. [1] describes the fix in version 7111.

Exploitation

An attacker must have valid authentication credentials to the ADManager Plus web interface. With authenticated access, the attacker can send crafted requests that inject OS commands into a vulnerable parameter or function. No additional privileges or user interaction beyond authentication is required.

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary operating system commands on the underlying server with the privileges of the application process. This can lead to full compromise of the ADManager Plus server, including data exfiltration, lateral movement, and further attacks.

Mitigation

The vulnerability is fixed in Zoho ManageEngine ADManager Plus version 7111 and later. [1] provides the release notes for version 7111. Users should upgrade to version 7111 or the latest available build. No workarounds are documented in the available references.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.