PoC-CVE-2024-26304
by GYATT - Saturday November 16, 2024 at 08:50 PM
#1
Hello, Breachforums community.

Today I'm bringing this ArubaOS RCE exploit to the table, here's the information about it:

CVE-2024-26304 is a critical remote code execution (RCE) vulnerability affecting ArubaOS due to a buffer overflow in its L2/L3 Management service. An attacker can exploit this by sending specially crafted packets to the PAPI (Process Application Programming Interface) UDP port 8211, resulting in the execution of arbitrary code with elevated privileges. 

ive used it once so far so let me know how it goes for you in the replies, reply below to get the GitHub checker thats hidden. 
Hidden Content
You must register or login to view this content.

This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Threatening forum members
Reply
#2
Some cool CVE , it sends request " /oauth/some_endpoint" , I think sending a request to that url returns some data , not sure what happens in the backed and why it happens , so according to code its named as memory dump , the the bytes returned are stored in a variable , its cleaned and checks for session tokens , the session tokens are then validated and hijacked . well it might be interesting to read more about it .
I Love Data
[Image: Capture.png]
I am gonna be  a criminal , Hehehe
Reply
#3
Lets see how its works. Anyways thanks
Reply
#4
okei thanks dude
This forum account is currently banned. Ban Length: (Permanent)
Ban Reason: Leeching | http://breached26tezcofqla4adzyn22notfqw...an-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  CVE-2024-21006 - Oracle WebLogic Server - HIGH tkqz 2 617 04-09-2025, 11:05 PM
Last Post: 9anatnaja7
  CVE-2024-43363 Poc result 29 2,185 04-09-2025, 12:53 AM
Last Post: slabadaba
  POC-CVE-2024-23113 result 106 6,526 04-07-2025, 03:59 PM
Last Post: g3oxn
  Outlook CVE-2024-21413 for RCE: Hacking through a letter Loki 51 4,022 04-02-2025, 10:39 PM
Last Post: JosueRobas8034
  Poc-CVE-2024-8275 result 36 2,462 04-02-2025, 07:03 AM
Last Post: latete_soufleur2

Forum Jump:


 Users browsing this thread: 1 Guest(s)