Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791)
Description
Detects the use of argument injection in the Commvault qlogin command - potential exploitation for CVE-2025-57791.
An attacker can inject the -localadmin parameter via the password field to bypass authentication and gain a privileged token.
Query · sigma
selection: CommandLine|contains|all: - qlogin - ' -cs ' - ' -localadmin' - ' -clp ' - _localadmin__ condition: selection
Known false positives
- Unknown