Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
99Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 10epss 53%
de la publicación al arma0 días
Publicada en NVD20 jun
1ª PoC20 jun
metasploit19 jun
VulnCheck19 jun
probabilidad de explotación
53%top 1% de las CVE
explotación observada
síVulnCheck
61 exploit(s) público(s)
Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
pterodactyl · panelPoCs públicas encontradas — 61
exploitdbwww.exploit-db.com/exploits/52341no verificadogithubgithub.com/YoyoChaud/CVE-2025-49132★ 25githubgithub.com/Zen-kun04/CVE-2025-49132★ 17githubgithub.com/malw0re/CVE-2025-49132-Mods★ 12githubgithub.com/63square/CVE-2025-49132★ 5githubgithub.com/popyue/CVE-2025-49132★ 4githubgithub.com/qiaojojo/CVE-2025-49132_poc★ 4githubgithub.com/0xtensho/CVE-2025-49132-poc★ 3githubgithub.com/GRodolphe/CVE-2025-49132_poc★ 3githubgithub.com/str1keboo/CVE-2025-49132★ 3githubgithub.com/dollarboysushil/CVE-2025-49132-Pterodactyl-Panel-Unauthenticated-Remote-Code-Execution-RCE-★ 3githubgithub.com/rippsec/CVE-2025-49132-PHP-PEAR★ 3githubgithub.com/pxxdrobits/CVE-2025-49132★ 2githubgithub.com/symphony2colour/HTB-Pterodactyl-RCE-CVE-2025-49132★ 1githubgithub.com/matesz44/CVE-2025-49132★ 1githubgithub.com/thealchimist86/CVE-2025-49132-Pterodactyl-Panel-RCE★ 1githubgithub.com/Pwndalf/CVE-2025-49132-PoC★ 1githubgithub.com/ramzihafiz/CVE-2025-49132★ 1githubgithub.com/vimmwy/CVE-2025-49132★ 1githubgithub.com/Ahmedf000/CVE-2025-49132_HTB_SEASON10★ 0githubgithub.com/typicalsmc/CVE-2025-49132-PoC★ 0githubgithub.com/melonlonmeo/CVE-2025-49132★ 0githubgithub.com/WebSafety-2tina/CVE-2025-49132★ 0githubgithub.com/kerburenthusiasm/CVE-2025-49132-PoC★ 0githubgithub.com/karimelsheikh1/HTB-Pterodactyl-Writeup★ 0githubgithub.com/scroollocker/CVE-2025-49132★ 0githubgithub.com/nik123-py/CVE-2025-49132_HTB_SEASON10★ 0githubgithub.com/4nuxd/CVE-2025-49132★ 0githubgithub.com/V0idW1re/HTB-Pterodactyl-Writeup★ 0githubgithub.com/yurahshell/CVE-2025-49132★ 0vulncheckvulncheck.com/xdb/62fba677a15cno verificadovulncheckvulncheck.com/xdb/b5e1a9cf356ano verificadovulncheckvulncheck.com/xdb/3d29769012ddno verificadovulncheckvulncheck.com/xdb/c2c106ebd6e0no verificadovulncheckvulncheck.com/xdb/9a716fc13bb0no verificadovulncheckvulncheck.com/xdb/27478c3c78a9no verificadovulncheckvulncheck.com/xdb/4a43ddc95aa5no verificadovulncheckvulncheck.com/xdb/1ee587c76421no verificadovulncheckvulncheck.com/xdb/567dfdc818e6no verificadovulncheckvulncheck.com/xdb/1d225955a5beno verificadovulncheckvulncheck.com/xdb/bc8e85534e70no verificadovulncheckvulncheck.com/xdb/257322a955edno verificadovulncheckvulncheck.com/xdb/ecb27047a9f1no verificadovulncheckvulncheck.com/xdb/ee89cc59e31cno verificadovulncheckvulncheck.com/xdb/20f9996dd19bno verificadovulncheckvulncheck.com/xdb/9ee1016338d0no verificadovulncheckvulncheck.com/xdb/d14488c76804no verificadovulncheckvulncheck.com/xdb/a46e88978d3fno verificadovulncheckvulncheck.com/xdb/c53be3f0a3ecno verificadovulncheckvulncheck.com/xdb/86f1349d3268no verificadovulncheckvulncheck.com/xdb/1061c622231eno verificadovulncheckvulncheck.com/xdb/78762d166ba2no verificadovulncheckvulncheck.com/xdb/4524ceeb6459no verificadovulncheckvulncheck.com/xdb/23db4ac0642cno verificadovulncheckvulncheck.com/xdb/27db0ff02fafno verificadovulncheckvulncheck.com/xdb/7eafd91c79fdno verificadovulncheckvulncheck.com/xdb/4487fa27f075no verificadovulncheckvulncheck.com/xdb/5dffb08c1813no verificadovulncheckvulncheck.com/xdb/9cd3b1d94ac5no verificadovulncheckvulncheck.com/xdb/3092ae31c466no verificadovulncheckvulncheck.com/xdb/571b13ffff02no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.