In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python PoC exploit for CVE-2025-56015 against GenieACS, bundled with a vulnerable Dockerized GenieACS environment for testing. The main exploit logic is in exploit.py; the rest of the repository largely consists of a nested copy of a GenieACS container project used to stand up a reproducible lab. Exploit capabilities: exploit.py performs three core actions. First, it sends an unauthenticated PUT request to the GenieACS NBI /provisions/{name} endpoint to create a malicious JavaScript provision. That provision uses declare.constructor.constructor('return this')() to escape the intended sandbox, recover the global process object, import Node.js net and child_process, and spawn /bin/bash -i. Second, it creates a preset via PUT /presets/{preset_name} that binds the malicious provision to the CWMP event "2 PERIODIC". Third, it simulates a TR-069/CWMP device by generating SOAP Inform traffic to the ACS endpoint on port 7547, causing GenieACS to process the preset and execute the provision. The net effect is remote code execution on the GenieACS host and a reverse shell to the attacker listener. The exploit is not merely a detector: it actively modifies server-side configuration and delivers a working payload. The reverse shell destination is configurable only by editing constants in the script (TARGET_IP, LHOST_IP, LPORT), which makes it operational but not highly modular. Repository structure: top-level files include README.md describing the vulnerability and usage, exploit.py containing the PoC, and docker-compose.yml that builds a vulnerable GenieACS instance from the embedded genieacs-vuln-arm64 directory. The nested genieacs-vuln-arm64 directory is a full container/deployment project with Dockerfile, Helm chart, compose file, entrypoint script, examples, and CI metadata. Its purpose is to provide a vulnerable GenieACS deployment rather than additional exploit logic. Notable targeting details: the README claims tested support for GenieACS v1.2.13 and suggests untested applicability to v1.2.14 through v1.2.16+. The exploit assumes exposed NBI and ACS services, lack of authentication on relevant NBI endpoints, and a Linux-based GenieACS host capable of making outbound TCP connections to the attacker.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.