Sploitus

Exploit for CVE-2025-49132

githubexploit · 2025-08-18

Exploit Code

README59 lines
## https://sploitus.com/exploit?id=5B52B1EC-F6BA-5508-970F-5FC58BCD3A03
# CVE-2025-49132 PoC (Improved)

This is an improved version of the CVE-2025-49132 proof of concept exploit.

## CVE Information

- **CVE ID**: CVE-2025-49132
- **NVD Reference**: [https://nvd.nist.gov/vuln/detail/cve-2025-49132](https://nvd.nist.gov/vuln/detail/cve-2025-49132)
- **Wiz Database**: [https://www.wiz.io/vulnerability-database/cve/cve-2025-49132](https://www.wiz.io/vulnerability-database/cve/cve-2025-49132)

## Original Work

This improvement is based on the original PoC from [0xtensho/CVE-2025-49132-poc](https://github.com/0xtensho/CVE-2025-49132-poc/tree/main).

## Improvements

- **Code Quality**: Refactored to follow Python Black and PEP8 standards
- **Better HTTP Client**: Replaced `os.system()` with `requests` library for more reliable HTTP requests
- **Descriptive Variables**: Renamed variables for better code readability
- **CLI Interface**: Added proper command-line argument parsing with help messages
- **Error Handling**: Improved error handling and user feedback

## Usage

```bash
python poc.py --host  --command 
```

### Examples

```bash
# Execute 'whoami' command
python poc.py --host 192.168.1.100 --command "whoami"

# Execute 'id' command
python poc.py --host example.com --command "id"
```

### Options

- `--host`, `-H`: Target host (required)
- `--command`, `-c`: Command to execute on target (required)
- `--help`, `-h`: Show help message

## Requirements

```
requests>=2.25.0
```

Install with:
```bash
pip install requests
```

## Disclaimer

This tool is for educational and authorized penetration testing purposes only. Only use on systems you own or have explicit permission to test.# CVE-2025-49132_poc