grep -l "Privilege Escalation" ./machines (2)

Connected [Linux]
Easy
FreePBXAsteriskSQL InjectionDefault CredentialsDatabase ManipulationSysadmin Hook +2
▲ pwned // not yet retired
Expressway [Linux]
Easy
IKEv1 Aggressive Mode PSK hash capture and offline brute-force reveals SSH credentials; custom sudo 1.9.17 binary is exploited via CVE-2025-32463 NSS library injection to achieve root.
ikeikev1aggressive-modepskipsecsudo +3
● pwned