An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (byob_unauth_rce.rb) targeting two critical vulnerabilities in the BYOB (Build Your Own Botnet) web GUI: CVE-2024-45256 (unauthenticated arbitrary file write) and CVE-2024-45257 (authenticated command injection). The exploit works in two stages: first, it uploads a malicious SQLite database to create a new admin user without authentication; second, it logs in as the new admin and exploits a command injection vulnerability in the payload generation endpoint to execute arbitrary commands (such as fetching and running a reverse shell payload). The module is fully weaponized, supporting customizable payloads and leveraging Metasploit's HTTP client/server mixins. The main endpoints targeted are '/api/file/add' for file upload and '/api/payload/generate' for command injection. The code is written in Ruby and structured as a standard Metasploit exploit module.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.