Metasploit Wrap-Up 12/05/2025

Dec 5 2025

Twonky Auth Bypass, RCEs and RISC-V Reverse Shell Payloads

This was another fantastic week in terms of PR contribution to the Metasploit Framework. Rapid7’s very own Ryan Emmons recently disclosed CVE-2025-13315 and CVE-2025-13316 which exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). The auxiliary module Ryan submitted which exploits both of these CVEs was released this week. Community contributor Valentin Lobsein aka Chocapikk has returned to the PR queue with a welcomed vengeance. Two modules from Chocapikk were landed this week, a Monsta FTP downloadFile Remote Code Execution module along with a WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE. In addition to some awesome module content, community contributor bcoles added Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.

New module content (5)

Twonky Server Log Leak Authentication Bypass

Author: remmons-r7

Type: Auxiliary

Pull request: #20709 contributed by remmons-r7 

Path: gather/twonky_authbypass_logleak 

AttackerKB reference: CVE-2025-13316

Description: This module exploits two CVEs: CVE-2025-13315 and CVE-2025-13316. Both CVEs exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). Then, because the module uses hardcoded keys, it decrypts those credentials.

Monsta FTP downloadFile Remote Code Execution

Authors: Valentin Lobstein chocapikk@leakix.net, msutovsky-r7, and watchTowr Labs

Type: Exploit

Pull request: #20718 contributed by Chocapikk 

Path: multi/http/monsta_ftp_downloadfile_rce 

AttackerKB reference: CVE-2025-34299

Description: This add module for CVE-2025-34299. The module exploits a vulnerability in the downloadFile action which allows an attacker to connect to a malicious FTP server and download arbitrary files to arbitrary locations on the Monsta FTP server.

WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE

Authors: Emiliano Versini, Khaled Alenazi (Nxploited), Valentin Lobstein chocapikk@leakix.net, and dledda-r7

Type: Exploit

Pull request: #20720 contributed by Chocapikk 

Path: multi/http/wp_ai_engine_mcp_rce 

AttackerKB reference: CVE-2025-11749

Description: This adds a new exploit module for an unauthenticated vulnerability in the WordPress AI Engine plugin, which has over 100,000 active installations. The vulnerability allows an attacker to create an administrator account via the MCP (Model Context Protocol) endpoint without authentication, then upload and execute a malicious plugin to achieve remote code execution. The vulnerability is being tracked as CVE-2025-11749.

Linux Command Shell, Reverse TCP Inline

Authors: bcoles bcoles@gmail.com and modexp

Type: Payload (Single)

Pull request: #20712 contributed by bcoles 

Path: linux/riscv32le/shell_reverse_tcp

Description: This adds Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.

Linux Command Shell, Reverse TCP Inline

Authors: bcoles bcoles@gmail.com and modexp

Type: Payload (Single)

Pull request: #20712 contributed by bcoles 

Path: linux/riscv64le/shell_reverse_tcp

Description: This adds Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.

Enhancements and features (3)

  • #20658 from jheysel-r7 - This adds a number of accuracy enhancements to the ldap_esc_vulnerable_cert_finder module. It also adds a CertificateAuthorityRhost datastore option to the esc_update_ldap_object module so the operator can specify an IP Address explicitly in cases where the hostname cannot be resolved via DNS.
  • #20677 from zeroSteiner - This enables sessions to MSSQL servers that require encryption. These changes add a new MsTds::Channel which leverages Rex's socket abstraction to facilitate the necessary encapsulation for the TLS negotiation.
  • #20741 from SaiSakthidar - This removes CAIN as an output format for collected hashes.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

Read more

Recommended Jobs

UK Commercial Account Executive (SMB)

1st Floor, Reading, United Kingdom, RG7 4SA Sales & BD
The SMB Account Executive is responsible for driving new business growth across the UKI region by managing the full sales cycle and building strong customer relationships. This role plays a key part in expanding Rapid7’s presence by positioning ou...

Enterprise Account Executive (Arizona)

Remote Location, AZ, United States, 85001 Sales & BD
*Actively looking for someone in Arizona*   In this role, you will partner cross-functionally with internal teams to drive net-new and renewal business opportunities with Enterprise accounts in AZ, from initial prospecting through negotiation and ...

Account Executive, Commercial Accounts

120 Causeway Street, Boston, MA, United States, 02114 Sales & BD
Rapid7’s Commercial Sales organization is seeking an Account Executive to join the team. You will serve as a strategic partner for clients in your assigned geography, helping them achieve a more secure digital future. In this quota carrying role, ...

Systems Administrator

Remote location, Pune, India, 411001 Information Technology
About the Role:We are looking for a Systems Administrator based in India to join our globally distributed IT infrastructure team. This individual will play a key role in supporting and managing our cloud infrastructure, enterprise endpoints, and s...

Senior Escalation Manager, Global Support

Water Street, Tampa, FL, United States, 33602 Business Support
Senior Escalation Manager, Global Support Job Summary We’re looking for a Senior Escalation Manager to lead Rapid7’s most complex, high-stakes customer escalations. In this role, you’ll ensure fast resolution, executive-ready communication, and ...

Technical Account Manager (Tampa/Austin)

Water Street, Tampa, FL, United States, 33602. Austin, TX, United States, 78701 Technical Support
Job Description As a Technical Account Manager (TAM), you will be responsible for managing the technical relationship between Rapid7 and its large enterprise and federal customers. As a trusted advisor, the TAM will manage the technical success of...