An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.
PoC: Havoc-C2-SSRF-poc
CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit
PoC: CVE-2024-41570-SSRF-RCE
Havoc SSRF to RCE
PoC: CVE-2024-41570
Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE
PoC: CVE-2024-41570-Havoc-C2-RCE
This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs
PoC: CVE-2024-41570-POC
CVE-2024-41570 is a critical SSRF vulnerability in Havoc C2 v0.7 that allows an unauthenticated attacker to send arbitrary network requests from the team server. This flaw can be exploited for internal network access or remote code execution (RCE).
PoC: Havoc-C2-SSRF-to-RCE
This is a modified version of the CVE-2024-41570 SSRF PoC from @chebuya chained with the auth RCE PoC from @hyperreality. This exploit is made to execute code remotely due to multiple vulnerabilities on Havoc C2 Framework. (https://github.com/HavocFramework/Havoc)
PoC: HavocPwn
Expanded Exploit based on CVE-2024-41570
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free