CVE-2025-12548Exploit

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-02-25); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-25: 1Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1PoC Mentioned / Linked · 2026-03-28: 1Exploit Tool / Code · 2026-02-25: 1Exploit Tool / Code · 2026-03-28: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 102-2503-2703-28
Signal classification1 categories
Exploit
3100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Metasploit Project@metasploit
    Exploit

    The latest #Metasploit Wrapup is here! 🎉 This week brings enhanced SMB NTLM relaying for better client compatibility (including smbclient), plus new modules for RCE in Eclipse Che (CVE-2025-12548), Barracuda ESG command injection (CVE-2023-2868), and an ESC/POS printer injector. Check it out at https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-03-27-2026/

    Post summary

    The announcement highlights new Metasploit modules that enable exploitation of specific CVEs, emphasizing the availability of new exploit code rather than patches or active attacks.

    01102864.3K
    252.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Metasploit adds 3 new exploit modules including CVE-2026-23767 (ESC/POS printer RCE), CVE-2025-12548 (Eclipse Che unauthenticated RCE), and CVE-2023-2868 (Barracuda ESG command injection). Enhanced NTLM relay compatibility with Linux smbclient. #DFIR_Radar https://t.co/kTThThSAHp

    Post summary

    Metasploit has released new exploit modules for CVE‑2026‑23767, CVE‑2025‑12548, and CVE‑2023‑2868, providing functional attack code and expanding NTLM relay compatibility.

    10010439
    1.2K followersView on X
  • Payload Forge@payloadforge
    Exploit

    1/2 War diary from LLM-assisted pentesting: needed a vulnerable che-machine-exec instance for my Metasploit PR (CVE-2025-12548, unauth RCE in Eclipse Che). Asked Grok 4 and Claude Sonnet 4.6. Both confidently wrong.

    Post summary

    The post notes work on a Metasploit module for CVE-2025-12548, an unauthenticated RCE in Eclipse Che, while LLMs failed to assist.

    1000052
    28 followersView on X

Explore more