Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-54322 — CVE-2025-54322 - XSpeeder SXZOS Pre-Auth RCE 0day Finder Quick | Kitploit
Tools/GitHubGitHub/sachinart/cve-2025-54322
ReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubsachinart/cve-2025-54322

CVE-2025-54322

CVE-2025-54322 - XSpeeder SXZOS Pre-Auth RCE 0day Finder Quick

View Repository
82109 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-54322 - XSpeeder SXZOS Pre-Auth RCE Scanner

License Python CVE

A multi-threaded vulnerability scanner for CVE-2025-54322, an unauthenticated remote code execution vulnerability in XSpeeder SXZOS firmware affecting ~70,000+ hosts globally.

📋 Table of Contents

  • About the Vulnerability
  • Features
  • Installation
  • Usage
  • Output
  • Disclaimer
  • Credits
  • Author

🔍 About the Vulnerability

CVE-2025-54322 is a critical pre-authentication remote code execution vulnerability discovered in XSpeeder SXZOS firmware, which powers SD-WAN devices, routers, and edge networking equipment.

Vulnerability Details

  • CVE ID: CVE-2025-54322
  • Vendor: XSpeeder (Chinese networking vendor)
  • Affected Product: SXZOS Firmware
  • Vulnerability Type: Pre-Authentication Remote Code Execution (RCE)
  • CVSS Score: 9.8+ (Critical)
  • Attack Vector: Network
  • Privileges Required: None
  • User Interaction: None
  • Impact: Complete system compromise with root privileges

Technical Details

The vulnerability exists in the Django-based web interface of SXZOS firmware:

  1. Vulnerable Endpoint: /?title=ABC&oIp=XXX&chkid=[base64_payload]
  2. Root Cause: Unsafe use of Python's eval() function on base64-decoded user input
  3. Authentication: None required (pre-auth)
  4. Execution Context: Root privileges
  5. Affected Hosts: ~70,000+ publicly accessible devices globally

Attack Flow

1. Calculate time-based nonce for X-SXZ-R header
2. Warm up session via /webInfos/ endpoint
3. Craft malicious payload with bypass string (#sUserCodexsPwd)
4. Base64 encode payload
5. Send exploit with exactly 3 query parameters
6. Server decodes and evaluates payload
7. Commands execute with root privileges

Bypass Mechanisms

The exploit bypasses multiple defense layers:

  • Nginx User-Agent Check: Spoofed with SXZ/2.3
  • Time-based Nonce: Calculated header X-SXZ-R: [0-6]
  • Session Requirement: Warmed via /webInfos/
  • String Filter: Bypassed with #sUserCodexsPwd comment
  • Parameter Count: Maintains exactly 3 query parameters

✨ Features

  • ✅ Multi-threaded scanning - Concurrent testing of multiple targets
  • ✅ SSL bypass - Handles self-signed and invalid certificates
  • ✅ Smart retry logic - 2 retry attempts per target
  • ✅ Clean output - Shows only vulnerable hosts
  • ✅ Real-time file writing - Saves results to vuln-confirm.txt immediately
  • ✅ Progress tracking - Live progress updates every 50 hosts
  • ✅ Thread-safe operations - Safe concurrent file and console operations
  • ✅ Accurate detection - Regex-based validation of command execution
  • ✅ PoC-matched logic - Follows original exploit methodology

🚀 Installation

Prerequisites

  • Python 3.7 or higher
  • pip package manager

Setup

# Clone the repository
git clone https://github.com/Sachinart/CVE-2025-54322.git
cd CVE-2025-54322

# Install required dependencies
pip install -r requirements.txt

Dependencies

Create a requirements.txt file:

requests>=2.31.0
urllib3>=2.0.0

📖 Usage

Basic Usage

python3 scanner.py targets.txt

Advanced Usage

# Scan with custom thread count (default: 10)
python3 scanner.py targets.txt 20

# Scan with maximum threads for faster results
python3 scanner.py targets.txt 50

# Scan with conservative thread count
python3 scanner.py targets.txt 5

Target File Format

Create a targets.txt file with one target per line:

https://192.168.1.100:4433
https://10.0.0.50:8443
https://example.com:4433
http://vulnerable-device.local

Example Session

$ python3 scanner.py targets.txt 20

╔═══════════════════════════════════════════════════════════════╗
║     XSpeeder SXZOS (CVE-2025-54322) RCE Scanner              ║
║     Pre-Auth Root RCE Vulnerability Checker                   ║
║     Showing: VULNERABLE HOSTS ONLY                            ║
╚═══════════════════════════════════════════════════════════════╝

[*] Loaded 2338 targets from targets.txt
[*] Using 20 concurrent threads
[*] Vulnerable hosts will be saved to: vuln-confirm.txt
[*] Starting scan...

======================================================================
[+] VULNERABLE: https://27.40.80.93:4433
[+] Status: VULNERABLE - RCE Confirmed
[+] HTTP Status: 500
[+] Output: uid=0(root) gid=0(root)
======================================================================

[*] Progress: 50/2338 | Found: 12 vulnerable
[*] Progress: 100/2338 | Found: 24 vulnerable

======================================================================
[*] SCAN COMPLETE
======================================================================
[*] Total Time: 890.45 seconds
[*] Total Targets Scanned: 2338
[*] Vulnerable Hosts Found: 156
[*] Success Rate: 6.67%
======================================================================

📊 Output

Console Output

The scanner displays:

  • Real-time vulnerable host discoveries
  • Progress updates every 50 hosts
  • Final summary with statistics
  • Clean, organized results

File Output (vuln-confirm.txt)

XSpeeder SXZOS CVE-2025-54322 - Vulnerable Hosts
Scan started: 2025-12-27 15:30:45
======================================================================

https://27.40.80.93:4433
Status: VULNERABLE - RCE Confirmed
Output: uid=0(root) gid=0(root)
----------------------------------------------------------------------
https://27.40.83.189:4433
Status: VULNERABLE - RCE Confirmed
Output: uid=0(root) gid=0(root)
----------------------------------------------------------------------

======================================================================
Scan completed: 2025-12-27 15:45:30
Total scanned: 2338
Vulnerable: 156
Time taken: 890.45 seconds

🎯 Thread Recommendations

Target CountRecommended ThreadsExpected Time
1-105 threads~1-2 min
10-5010 threads~3-5 min
50-10020 threads~5-10 min
100-50030 threads~10-20 min
500+40-50 threads~20+ min

⚠️ Disclaimer

This tool is provided for educational and authorized security testing purposes only.

Legal Notice

  • Only test systems you own or have explicit written permission to test
  • Unauthorized access to computer systems is illegal in most jurisdictions
  • The author assumes no liability for misuse of this tool
  • By using this tool, you agree to use it responsibly and ethically
  • This tool is for security research and penetration testing only

Responsible Disclosure

If you discover vulnerable systems:

  1. Do not exploit beyond confirming the vulnerability
  2. Report findings to the system owner immediately
  3. Allow reasonable time for remediation
  4. Do not publicly disclose specific vulnerable hosts

Ethical Use

  • DO: Use for authorized penetration testing
  • DO: Use for security research with permission
  • DO: Report vulnerabilities responsibly
  • DON'T: Use for unauthorized access
  • DON'T: Use for malicious purposes
  • DON'T: Publicly expose vulnerable systems

🛡️ Mitigation

For System Administrators

If you manage XSpeeder SXZOS devices:

Download Tool