
# CVE-2025-0282: Remote Code Execution Vulnerability in [StorkS]
Storks is a Python-based Proof-of-Concept (PoC) tool designed to demonstrate a critical Remote Code Execution (RCE) vulnerability, identified as CVE-2025-0282, in a specific network appliance. This vulnerability can be exploited by sending a crafted POST request to a specific endpoint. This tool is intended for educational and research purposes only.
Disclaimer: Please note that using this tool on systems without proper authorization is illegal and unethical. We are not responsible for any damages or actions caused by misuse of this tool. Please use it responsibly and at your own risk.
The /dana-na/auth/url_default/welcome.cgi endpoint is vulnerable to a buffer overflow, which can be exploited to achieve remote code execution by overwriting the return address on the stack. This allows the attacker to execute arbitrary shellcode, potentially leading to full control of the system. The exploit uses Return-Oriented Programming (ROP) to bypass ASLR and execute the shell code correctly.
Prerequisites:
requests, struct, socket, ssl, urllib3, pymongo, openai, bson and google-generativeai.msfvenom.Obtain Storks: To obtain the full Storks application and secure download link, please contact me on Telegram: @AnonStorks
Set up a Listener: Configure your system to listen on the specified IP and port.
Run the Exploit: After obtaining the code, you can execute the Storks application and follow the on-screen prompts.
python exploit.py <target_ip>
<target_ip> with the IP address of the vulnerable target.Wait for success or error: The code will attempt the exploit until it succeeds or until you stop it.
The exploit attempts to gain code execution by exploiting a buffer overflow vulnerability present in the /dana-na/auth/url_default/welcome.cgi endpoint. The code attempts to overwrite the return address and inject shellcode into the vulnerable process. The code uses the following steps:
The Storks application is provided "as is" without any warranty. The author is not responsible for any damages or illegal actions caused by the use of this code. Use responsibly and ethically.
Contributions are welcome. Feel free to open pull requests or report issues.
For full code and secure download link, please contact me on Telegram: @AnonStorks