
Critical directory traversal in Pterodactyl Panel v1.11.10 leads to unauthenticated RCE via PHP-PEAR exploitation chain. CVE-2025-49132 combines with PEAR pearcmd technique enabling arbitrary webshell deployment. Key technical details: • Endpoint /locales/locale.json bypasses auth middleware, accepts unsanitized locale/namespace parameters • Path traversal: locale=../../../../../usr/share/php/PEAR&namespace=pearcmd enables arbitrary .php file inclusion • PEAR pearcmd.php accepts config-create command via register_argc_argv, writes attacker-controlled content to disk • Payload: `<?=system($_REQUEST[0]);?>` creates webshell at /tmp/shell.php accessible via LFI Attack chain methodology: • Initial recon reveals Pterodactyl Panel v1.11.10 with PHP-PEAR enabled • Directory traversal to include pearcmd.php with malicious config creation • Second request includes written webshell for command execution • Database credential extraction leads to bcrypt hash cracking: !QAZ2wsx • Privilege escalation via CVE-2025-6018 (PAM environment bypass) + CVE-2025-6019 (libblockdev/udisks XFS mounting) Hunt for HTTP requests to `/locales/locale.json` with `../` sequences in locale parameter and suspicious namespace values targeting pearcmd.php. #DFIR_Radar
Post summary
The entry details a full exploitation chain for CVE‑2025‑49132, including PoC code, traversal vector, and post‑exploit actions, classifying it as an exploit.




