References https://nvd.nist.gov/vuln/detail/CVE-2025-4428 https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM https://cve.imfht.com/detail/CVE-2025-4428?lang=en https://cloud.tencent.com/developer/article/2574713 https://cloud.tencent.com/developer/article/2651898 https://blog.eclecticiq.com/china-nexus-threat-actor-actively-exploiting-ivanti-endpoint-manager-mobile-cve-2025-4428-vulnerability https://www.ionix.io/threat-center/cve-2025-4428/ https://www.wiz.io/blog/ivanti-epmm-rce-vulnerability-chain-cve-2025-4427-cve-2025-4428 https://projectdiscovery.io/blog/ivanti-remote-code-execution https://www.tenable.com/blog/cve-2025-4427-cve-2025-4428-ivanti-endpoint-manager-mobile-epmm-remote-code-execution https://github.com/xie-22/CVE-2025-4428 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-4428
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞PoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCccm-detect: Clear-Com Core Configuration Manager Panel - Detect智慧物联网综合服务平台ListFileManager存在目录枚举漏洞蓝凌EIS智慧协同平台 /Mobile/mobile_define.aspx/Getmobiles SQL 注入漏洞WP User Manager /profile/admin/about 文件包含漏洞(CVE-2026-9290)SteVe /steve/manager/signin 默认口令漏洞PoCCVE-2008-2052: Bitrix Site Manager 6.5 - Open RedirectPoCCVE-2025-13339: Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadPoCCVE-2026-10520: Ivanti Sentry - OS Command Injection