Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-4428 PoC — Remote Code Execution

Source
Associated Vulnerability
Title:Remote Code Execution (CVE-2025-4428)
Description:Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
Description
Ivanti EPMM Pre-Auth RCE Chain
Readme
# CVE-2025-4427 & CVE-2025-4428 Vulnerability Scanner

![Python Version](https://img.shields.io/badge/python-3.6%2B-blue)
![License](https://img.shields.io/badge/license-MIT-green)

Advanced detection tool for identifying systems vulnerable to the CVE-2025-4427 and CVE-2025-4428 exploit chain. This security scanner helps identify vulnerable endpoints and demonstrates proof-of-concept exploitation.

## Features

- 🛡️ **Vulnerability Detection**: Identifies vulnerable systems through signature analysis
- 💻 **Command Execution**: Allows safe testing of vulnerability via controlled command execution
- 🔄 **Retry Mechanism**: Automatic retry for failed connections
- 📄 **Logging System**: Detailed logging with file and console outputs
- 🌐 **Proxy Support**: Configurable proxy settings for traffic inspection
- 🔧 **Multi-Shell Support**: Compatible with both bash and sh environments
- 📊 **Output Redirection**: Save results to external files

## Installation

1. **Requirements**:
   - Python 3.6+
   - requests library

2. **Install dependencies**:
```bash
pip install requests
```

## Usage

### Basic Command

```
python scanner.py -H http://target-site.com/
```

### Full Syntax

```
python scanner.py -H [TARGET_URL] [OPTIONS]
```

### Options

| Parameter |                    Description                    |
| :-------: | :-----------------------------------------------: |
|    -H     |               Target URL (required)               |
|    -c     |        Command to execute (default: 'id')         |
|    -s     |                 Shell type [bash                  |
|    -x     | Proxy configuration (e.g.: http://127.0.0.1:8080) |
|    -t     |     Request timeout in seconds (default: 15)      |
|    -r     |      Connection retry attempts (default: 2)       |
|    -o     |                 Output file path                  |

## Examples

1. Basic vulnerability check:

```
python scanner.py -H https://example.com/
```

1. Custom command execution with proxy:

```
python scanner.py -H http://internal-server/ -c "uname -a" -x http://proxy:8080
```

1. Full test with output redirection:

```
python scanner.py -H http://test-site.com/ -s sh -t 30 -o results.txt
```

## Important Notes

- 🚨 **Legal Compliance**: Use only on authorized systems
- 🔒 **Security Advisory**: For testing purposes only
- ⚠️ **Ethical Warning**: Do not use for illegal activities
- 📝 **Best Practice**: Always verify results manually
- 🔍 **Accuracy**: False positives/negatives possible - use as initial screening tool

## Exit Codes

| Code |        Description         |
| :--: | :------------------------: |
|  0   | Vulnerable system detected |
|  1   |   No vulnerability found   |
|  2   |  Execution error occurred  |
## License

Distributed under MIT License. See `LICENSE` for full text.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →