grep -l "RCE" ./machines (5)

Connected [Linux]
Easy
FreePBXAsteriskSQL InjectionDefault CredentialsDatabase ManipulationSysadmin Hook +2
▲ pwned // not yet retired
Silentium [Linux]
Easy
FlowiseCVE-2025-58434Password Reset Token DisclosureAccount TakeoverCVE-2025-59528Custom MCP +10
▲ pwned // not yet retired
CCTV [Linux]
Easy
Default ZoneMinder credentials lead to RCE as www-data. Lateral movement via cracked bcrypt hash to SSH as mark, then sniffing Docker inter-container traffic for sa_mark credentials. Privilege escalation by abusing motionEye running as root to inject a reverse shell into camera event hooks.
ZoneMinderDefault CredentialsDockermotionEyeCredential SniffingRCE
● pwned
Pterodactyl [Linux]
Medium
Unauthenticated RCE via Pterodactyl Panel LFI (CVE-2025-49132), credential reuse for SSH, then privilege escalation via PAM session injection (CVE-2025-6018) chained with udisks2 XFS resize race condition (CVE-2025-6019) to obtain root.
CVE-2025-49132LFIpearcmdRCECVE-2025-6018CVE-2025-6019 +6
● pwned
MonitorsFour [Windows]
Easy
IDOR credential leak, Cacti SQL injection to stacked-query log poisoning RCE, and Docker Desktop API escape to root.
IDORCactiSQLiRCEDockerDocker Desktop Escape +3
● pwned