1Panel是中国1Panel社区的一个开源的Linux服务器运维管理面板。 1Panel 2.0.5及之前版本存在命令注入漏洞,该漏洞源于证书验证不完整,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | 1Panel | < 2.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2025-54424:1Panel 客户端证书绕过RCE漏洞 一体化工具 (扫描+利用) | https://github.com/Mr-xn/CVE-2025-54424 | POC Details |
| 2 | CVE-2025-54424: 1Panel TLS client cert bypass enables RCE via forged CN 'panel_client' using a bundled scanning and exploitation tool. Affected: <= v2.0.5. 🔐 | https://github.com/hophtien/CVE-2025-54424 | POC Details |
| 3 | 🔍 Exploit the CVE-2025-54424 RCE vulnerability in 1Panel, enabling unauthorized command execution through a certification bypass tool for scanning and exploitation. | https://github.com/bejbitoilet5125521/CVE-2025-54424 | POC Details |
| 4 | None | https://github.com/anonnymous5/1Panel-CVE-2025-54424- | POC Details |
No comments yet