S4E just found a high [ai] pa ssl inspection control
critical·Product Based Web Vulnerabilities·Updated Jun 21, 2025

CVE-2025-49132 Scanner

CVE-2025-49132 Scanner - Remote Code Execution vulnerability in Pterodactyl Panel

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-49132
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated. With the ability to execute arbitrary code it could be used to gain access to the Panel's server, read credentials from the Panel's config, extract sensitive information from the database, access files of servers managed by the panel, etc. This issue has been patched in version 1.11.11. There are no software workarounds for this vulnerability, but use of an external Web Application Firewall (WAF) could help mitigate this attack.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
panelby pterodactyl
< 1.11.11
Updated Aug 19, 2026View on NVD →
Detail

Pterodactyl Panel is an open-source tool designed for managing game servers. It is widely utilized by game administrators and hosting providers to streamline server deployment and maintenance. The software provides a unified interface through which users can easily manage multiple game server instances across different physical or virtual machines. Its user-friendly design and flexibility make it an attractive solution for those needing efficient game server management. Additionally, its open-source nature allows developers to customize the panel to fit specific needs. This versatility and the wide range of supported games have led to its widespread adoption in the gaming community.

The vulnerability in question is a Remote Code Execution (RCE) flaw within the Pterodactyl Panel. This type of vulnerability allows an attacker to execute arbitrary code on the server hosting the panel. By exploiting this flaw, an unauthenticated user can potentially run malicious commands, which in turn can compromise the entire server. This vulnerability is particularly dangerous due to its high severity, making affected systems highly susceptible to full server compromise. It underscores the critical importance of robust security measures and timely software updates.

The vulnerability is triggered by accessing the endpoint '/locales/locale.json' with specific query parameters such as 'locale' and 'namespace'. A crafted request can manipulate these parameters to escalate privileges and execute arbitrary commands. The server’s response reveals application details that indicate successful exploitation. Such exploitation is enabled by improper sanitization of user input, which allows malicious actors to navigate through sensitive directories and access configuration files. This exploitation method can subsequently lead to severe security breaches.

If this vulnerability is exploited, attackers could gain unauthorized access to the server and the data it contains. This could lead to data exfiltration, unauthorized data modifications, or complete system takeover. Servers running Pterodactyl Panel could be used to launch further attacks within the network or to other systems. Sensitive information such as user credentials, configuration details, and server data could be exposed and manipulated. Overall, the exploitation of this vulnerability poses significant security and operational risks for affected systems.

REFERENCES

Solution Advice
  • Upgrade to Pterodactyl version 1.11.11 or later to patch the vulnerability.
  • Consider deploying a Web Application Firewall (WAF) to help mitigate potential attacks.
  • Regularly audit server configurations and access permissions to minimize exposure.
  • Conduct security training for administrators to recognize and respond to potential exploitation attempts.
  • Monitor server activity logs for any suspicious or unusual actions that may indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.