Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-26056 — Proof-of-concept exploit for CVE-2025-26056, an OS command injection vulnerability in a web application's MTR report generation endpoint, allowing arbitrary command execution. | Kitploit
Tools/GitHubGitHub/rohan-pt/cve-2025-26056
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and Control
GitHubrohan-pt/cve-2025-26056

CVE-2025-26056

Proof-of-concept exploit for CVE-2025-26056, an OS command injection vulnerability in a web application's MTR report generation endpoint, allowing arbitrary command execution.

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-26056

Auhtor: Rohan Deshpande

OS Command Injection

Summary

OS command injection is a security vulnerability that allows an attacker to execute arbitrary commands on a host operating system via a vulnerable application. This can lead to unauthorized access, data breaches, and system compromise.

Impact

The impact of OS command injection can include unauthorized access to system resources, data theft, system compromise, and potential full control over the affected server, leading to severe security breaches and operational disruptions.

Affected URL

http://:/generateMTRReport

Recommendation

To mitigate OS command injection vulnerabilities, validate and sanitize all user inputs, use parameterized commands or APIs, and implement least privilege principles to limit the execution context of applications. Regular security testing and code reviews are also essential to identify and remediate potential weaknesses.

Proof of Concept

  1. Login to the console and navigate to Troubleshoot → MTR.
  2. Enter IP and capture the request in burp.
  3. Try to fetch ‘<!--#exec%20cmd="/bin/cat%20/etc/passwd"-->’ file through parameter mtrIP and notice file displayed in HTTP response.
Download Tool