CVE-2024-25641 is a critical arbitrary file write vulnerability in Cacti prior to version 1.2.27. The flaw resides in the Package Import feature, specifically in the import_package() function in the import handling logic. The vulnerable code trusts filename and file content values supplied within imported XML package data and writes those files to the Cacti base path without adequately validating the destination path. Because path traversal sequences are not properly filtered, an authenticated user with the Import Templates permission can write files to attacker-controlled locations, including outside the intended directory. This behavior can be leveraged to place or overwrite PHP files on the web server and achieve arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script (exploit.py) plus a minimal README. The exploit targets CVE-2024-25641 in Cacti 1.2.26 and requires valid credentials (authenticated RCE). High-level flow: 1) Optional version check: GET /CHANGELOG and look for strings indicating 1.2.26. 2) Establish a requests.Session(), GET the Cacti root page, parse HTML with BeautifulSoup to extract the CSRF token (__csrf_magic). 3) Authenticate by POSTing credentials to /index.php. 4) Build a PHP reverse shell payload that connects back to attacker-supplied lhost:lport and spawns /bin/sh -i. 5) Create a malicious Cacti package: the script generates an RSA keypair, signs the payload and the XML package structure, base64-encodes payload/signatures/public key, then gzip-compresses the final XML and writes it locally as <random>.php.gz. 6) Upload the gzipped package to Cacti’s package importer endpoint (/package_import.php with preview/import parameters). It then parses the response HTML to find the uploaded file’s input element (by matching the random filename in the title attribute) to obtain the file ID. 7) Finalize the import by POSTing to /package_import.php?header=false with the file ID selected, causing the payload to be written server-side as resource/<random>.php. 8) Trigger code execution by GET /resource/<random>.php, which initiates the reverse shell callback. Notable characteristics: - Network-based authenticated exploit; no scanning/detection-only behavior. - Drops a web-accessible PHP file under /resource/ and executes it via HTTP. - Uses cryptography library to generate/sign package content, indicating the vulnerability involves trusting attacker-controlled package signatures when “trust_signer” is enabled in the import workflow. - Cleans up only the local .gz file; it does not remove the remote PHP payload after execution.
This repository provides an exploit for CVE-2024-25641, a remote code execution vulnerability in Cacti version 1.2.26. The main exploit logic is implemented in 'thorn.py', which automates the process of checking the Cacti version, authenticating to the web interface, generating a malicious PHP reverse shell payload, and uploading it to the target server. The payload is either taken from 'payload/shell.php' or dynamically generated within the Python script. Once uploaded, the script triggers the payload, causing the target to connect back to the attacker's machine (default IP: 10.10.14.19, port: 3333) and provide a remote shell. The exploit requires the attacker to have access to the Cacti web interface and to configure their hosts file for proper domain resolution. The repository contains 5 files: a Python exploit script (thorn.py), a PHP reverse shell payload (payload/shell.php), a requirements file, a README, and a license. The exploit is operational and provides a working reverse shell if the target is vulnerable and properly configured.
This repository contains a single Metasploit module (modules/exploits/multi/http/cacti_package_import_rce.rb) that exploits CVE-2024-25641, an arbitrary file write vulnerability in Cacti versions prior to 1.2.27. The exploit abuses the 'Import Packages' feature to upload a specially crafted package containing a PHP payload, which is then executed to achieve remote code execution (RCE) as the web server user. The module supports multiple payload types, including PHP Meterpreter and command-based reverse shells for both Linux and Windows targets. Authentication is required, and the attacker must have access to the 'Import Packages' feature. The exploit interacts with the Cacti web interface via HTTP(S), specifically targeting endpoints such as '/cacti/index.php' and '/cacti/package_import.php'. The module is weaponized, allowing for customizable payloads and automated cleanup of dropped files. The repository is structured as a typical Metasploit exploit module, written in Ruby, and is intended for use within the Metasploit Framework.
This repository provides a working exploit for CVE-2024-25641, a remote code execution vulnerability in Cacti 1.2.26. The exploit targets authenticated users with the 'Import Templates' permission, leveraging the 'Package Import' feature to upload and execute arbitrary PHP code on the server. The main script, 'cacti_exploit.py', automates the attack: it logs into the Cacti web interface, crafts a malicious package containing a PHP payload (by default, 'php/reverse_shell.php'), uploads it via the vulnerable endpoint, and provides the attacker with the URL to trigger the payload. The included PHP payload is a standard reverse shell, which must be configured with the attacker's IP and port. The exploit requires Python 3 and several dependencies listed in 'requirements.txt'. The repository is well-structured, with clear separation between the exploit script, payload, and documentation. The attack vector is network-based, requiring access to the Cacti web interface and valid credentials. No fake or detection-only scripts are present; this is a functional exploit with operational-level maturity.
This repository provides a working proof-of-concept exploit for CVE-2024-25641, targeting Cacti version 1.2.26. The exploit is implemented in Python (exploit.py) and automates the process of authenticating to the Cacti web interface, uploading a maliciously crafted GZIP file containing a PHP reverse shell via the 'Package Import' feature, and then triggering the payload to establish a reverse shell connection to the attacker's machine. The exploit requires valid credentials for a user with the 'Import Templates' permission. The payload is a standard PHP reverse shell, and the exploit demonstrates the vulnerability by achieving remote code execution on the target server. The repository also includes a README with usage instructions, references, and a requirements.txt listing necessary Python dependencies. No detection or fake code is present; this is a functional exploit for authenticated RCE in Cacti 1.2.26.
This repository contains a Python proof-of-concept exploit for CVE-2024-25641, a vulnerability in the Cacti network monitoring tool. The exploit automates the process of authenticating to a Cacti instance, uploading a malicious package (test.xml.gz), and triggering a reverse shell to the attacker's machine. The exploit requires valid credentials and the target must be running a vulnerable version of Cacti. The main script (exploit.py) uses the requests library to interact with the web application, handles CSRF tokens, and performs the necessary steps to achieve remote code execution. The payload is a bash reverse shell using netcat and mkfifo. The README.md provides usage instructions and requirements. No framework is used; this is a standalone PoC exploit.
This repository provides a fully automated exploit for CVE-2024-25641, targeting Cacti version 1.2.26. The exploit leverages an authenticated arbitrary file write vulnerability in the 'Package Import' feature, allowing an attacker with valid credentials and the 'Import Templates' permission to upload and execute arbitrary PHP code on the server. The main script, 'exploit.py', automates the process: it generates a malicious PHP script that downloads and executes a reverse shell payload (an ELF binary generated by msfvenom), logs into the target Cacti instance, uploads the malicious package, and triggers the payload to establish a reverse shell connection to the attacker's machine. The repository includes a README with usage instructions and a requirements.txt for dependencies. The exploit requires the attacker to run a local HTTP server to serve the payload and a netcat listener to receive the shell. The code is operational and provides a working end-to-end exploit chain for authenticated RCE on Cacti 1.2.26.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.