
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10020 is an authenticated command injection vulnerability in the Custom Script component of Zohocorp ManageEngine ADManager Plus. It affects all versions before build 8024 (including 8.0-8001 through 8.0-8023 and all versions prior to 8.0), and was fixed on September 19, 2025, with public disclosure on October 21, 2025. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) per NVD, and 9.9 (Critical) per ENISA/Zohocorp's own scoring (ManageEngine Advisory, Red Hat CVE).
The root cause is improper neutralization of special elements used in OS commands (CWE-77) within the Custom Script component of ADManager Plus. An authenticated attacker with low-level privileges can inject arbitrary commands through this component, which fails to adequately sanitize user-supplied input before passing it to the underlying operating system. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once credentials are obtained. The vulnerability can lead to remote code execution (RCE) on the server (ManageEngine Advisory, Red Hat CVE).
Successful exploitation allows an authenticated attacker to execute arbitrary system commands on the ADManager Plus server, resulting in full compromise of confidentiality, integrity, and availability. An attacker could gain unauthorized access to sensitive Active Directory data, modify or delete data, disrupt service availability, and potentially use the compromised server as a pivot point for lateral movement within the Active Directory environment (ManageEngine Advisory, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.79%, indicating a currently low probability of exploitation in the near term. The vulnerability was responsibly disclosed by researcher "bitxer" through Zoho's Bug Bounty program and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (ManageEngine Advisory, Red Hat CVE).
Zohocorp released a fix in ADManager Plus build 8024 on September 19, 2025. All users running build 8023 or earlier should upgrade immediately by installing the available service pack. As interim mitigations, organizations should implement network access controls to restrict exposure of the ADManager Plus interface, limit authentication credentials to necessary personnel only, and monitor Custom Script component activity for suspicious command patterns (ManageEngine Advisory).
The vulnerability received standard coverage from vulnerability tracking platforms and security aggregators shortly after disclosure on October 21, 2025. Greenbone included it in their October 2025 threat report, and it was noted by the security community on Mastodon/infosec.exchange. No major vendor statements beyond Zoho's own advisory or significant researcher commentary beyond the bug bounty reporter acknowledgment have been observed (Greenbone Threat Report).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."