OpenNetAdmin 18.1.1 contains a critical remotely exploitable vulnerability that can lead to privilege escalation. The specific vulnerable function or code path is not identified in the provided content, so more detailed technical characterization is currently not available. Public exploit disclosure indicates that exploit details exist and may be used by attackers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Single-file Python exploit targeting OpenNetAdmin RCE via CVE-2019-25065. The repository contains one script, exploit.py, which provides two CLI subcommands: 'version' and 'exploit'. The version routine sends an HTTP POST to the user-supplied ONA URL with xajax=window_open and xajaxargs[]=app_about, then parses the HTML response for an OpenNetAdmin version string. The exploit routine sends an HTTP POST with xajax=window_submit and crafted xajaxargs values, abusing the 'tooltips'/'ping' request flow by injecting shell metacharacters into the ip parameter. It wraps command output with a randomly generated UUID separator so the script can reliably extract stdout/stderr from the returned page using regex. The exploit is operational but simple: it does not include persistence, staging, or automated post-exploitation, only arbitrary command execution and output retrieval over HTTP.
This repository contains a single standalone Python exploit script, exploit.py, targeting OpenNetAdmin command injection identified as CVE-2019-25065. The script is not part of a larger framework. It uses the requests library to send HTTP POST requests to a user-supplied ONA URL and supports two modes via argparse subcommands: a version-check mode and an exploitation mode. The version-check mode calls the xajax action window_open with app_about to extract the OpenNetAdmin version from the returned HTML using a regex. The exploit mode abuses the xajax window_submit workflow with arguments tooltips, a crafted ip parameter, and ping. The ip field is injected with shell metacharacters to append an arbitrary command, wrapping output between randomly generated UUID separators so the script can reliably parse command output from the HTTP response. The exploit provides remote arbitrary command execution and returns stdout/stderr to the operator. Repository structure is minimal: one Python file serving as both CLI entry point and exploit implementation, with helper functions for version retrieval and exploitation.
This repository contains a single Metasploit module targeting a command injection vulnerability (CVE-2019-25065) in OpenNetAdmin versions 8.5.14 through 18.1.1. The exploit leverages a vulnerable HTTP POST parameter in the web application's ping functionality to achieve remote code execution. The module is written in Ruby and uses Metasploit's HttpClient and CmdStager mixins to deliver a payload, typically a reverse shell (meterpreter), to the target Linux system. The main entry point is the Ruby file 'modules/exploits/unix/webapp/opennetadmin_ping_cmd_injection.rb'. The exploit requires network access to the target's web interface (default path: /ona/login.php) and is fully weaponized, allowing for customizable payloads and automated exploitation through the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.