CVE-2025-54424 affects 1Panel, a Linux server management platform providing a web interface and MCP server for managing websites, files, containers, databases, and LLMs. In 1Panel versions 2.0.5 and earlier, the HTTPS communication channel between Core and Agent endpoints performs incomplete certificate verification during certificate validation. According to the advisory, an attacker can present a self-signed client certificate with CN=panel_client and bypass certificate authenticity checks. This allows unauthorized access to agent-facing interfaces, including sensitive WebSocket and node-management endpoints. Because those interfaces expose command-execution and other high-privilege administrative functionality, the authentication bypass can be chained directly into arbitrary command execution, resulting in remote code execution on managed systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python exploit (CVE-2025-54424.py) targeting a critical authentication bypass and remote code execution vulnerability in 1Panel <= v2.0.5. The vulnerability arises from the agent's TLS configuration, which accepts any client certificate (tls.RequireAnyClientCert) and only checks the CN field for 'panel_client', allowing attackers to generate a self-signed certificate and gain unauthorized access. The exploit script supports both single-target exploitation (providing an interactive remote shell via WebSocket) and mass scanning of targets for vulnerability. It dynamically generates the required certificate, performs an initial HTTPS check, and then connects to the WebSocket endpoint to execute arbitrary commands. The README provides detailed background, usage instructions, and endpoint documentation. The main attack vector is network-based, targeting the agent's HTTPS and WebSocket interfaces, typically on port 9999. The exploit is operational and provides a working RCE payload. The repository consists of three files: the main exploit script (CVE-2025-54424.py), a README with vulnerability and usage details, and a LICENSE file. The code is written in Python and is self-contained, requiring only standard and common third-party libraries.
This repository provides a Python exploit tool for CVE-2025-54424, a remote code execution (RCE) vulnerability in 1Panel due to client certificate authentication bypass. The main script, CVE-2025-54424.py, is a standalone tool that supports both scanning and exploitation modes. In scan mode, it can check multiple targets for vulnerability by attempting an authenticated HTTPS request and a WebSocket connection using a dynamically generated client certificate (CN=panel_client). In exploit mode, it provides an interactive shell over WebSocket to a single vulnerable target, allowing arbitrary command execution. The tool is designed for use in authorized, controlled environments and emphasizes safe, ethical testing as described in the README. The endpoints targeted are '/api/v2/dashboard/base/os' (HTTPS) for pre-check and '/api/v2/hosts/terminal' (WSS) for shell access. The repository contains one main code file, a README with detailed usage and ethical guidelines, and a license file.
This repository contains a single Python exploit script (CVE-2025-54424.py) targeting a remote code execution (RCE) vulnerability in 1Panel (<= v2.0.5) due to improper TLS client certificate validation. The exploit dynamically generates a self-signed certificate with CN=panel_client, which is accepted by the vulnerable agent due to the use of 'tls.RequireAnyClientCert' (does not verify CA). The script supports both single-target exploitation (providing an interactive shell via WebSocket) and mass scanning of targets for vulnerability. It interacts with the target's HTTPS and WebSocket endpoints, specifically /api/v2/dashboard/base/os for pre-check and /api/v2/hosts/terminal for command execution. The README provides detailed vulnerability analysis, usage instructions, and endpoint documentation. The exploit is operational, providing a working interactive shell if the target is vulnerable. No framework is used; the code is standalone Python.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.