CVE-2015-1497

Persistent Systems Radia Client Automation <9.1 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2015-1497. PoCs published by Metasploit, SlidingWindow, Ben Turner, including Metasploit module exploits/multi/misc/persistent_hpca_radexec_exec.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in HP Client Automation's Notify Daemon (radexecd.exe), which lacks authentication for execution requests. It supports both Windows and Linux targets, achieving remote code execution by injecting commands into the 'hide' command parameter.

Description

radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/36169

This Metasploit module exploits a command injection vulnerability in HP Client Automation's Notify Daemon (radexecd.exe), which lacks authentication for execution requests. It supports both Windows and Linux targets, achieving remote code execution by injecting commands into the 'hide' command parameter.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Client Automation 9.0.0
No auth needed
Prerequisites: Network access to TCP port 3465 · Target running HP Client Automation 9.0.0
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
by SlidingWindow · pythonremotemultiple
https://www.exploit-db.com/exploits/40491

This exploit demonstrates a command injection vulnerability in HP Client Automation (CVE-2015-1497) by sending crafted network packets to port 3465. It includes payloads for both Linux and Windows targets to add privileged users and establish reverse shells.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Client Automation (versions 7.9, 8.1, 9.0, 9.1)
No auth needed
Prerequisites: Network access to target on port 3465 · Target running vulnerable HP Client Automation software
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
by Ben Turner · rubyremotewindows
https://www.exploit-db.com/exploits/36206

This Metasploit module exploits a command injection vulnerability in Persistent Systems Client Automation (PSCA) by installing a malicious service via SMB and executing a payload. It targets versions 7.9, 8.1, 9.0, and 9.1 on Windows systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Persistent Systems Client Automation (PSCA) versions 7.9, 8.1, 9.0, 9.1
No auth needed
Prerequisites: Network access to target's SMB and PSCA service ports · Write access to an SMB share
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
by Ben Turner, juan vazquez · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/misc/persistent_hpca_radexec_exec.rb

This Metasploit module exploits a command injection vulnerability in HP Client Automation's Notify Daemon (radexecd.exe), which lacks authentication by default. It supports both Windows and Linux targets, achieving remote code execution via crafted commands.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: HP Client Automation 9.0.0 (Persistent Systems Client Automation)
No auth needed
Prerequisites: Network access to TCP port 3465 · Vulnerable version of HP Client Automation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/118382
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72612
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/36169
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-15-038/
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/36206
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/40491/

Scores

EPSS 0.7512
EPSS Percentile 99.4%

Details

CWE
CWE-94
Status published
Products (4)
persistent_systems/radia_client_automation 7.9
persistent_systems/radia_client_automation 8.1
persistent_systems/radia_client_automation 9.0
persistent_systems/radia_client_automation 9.1
Published Feb 16, 2015
Tracked Since Feb 18, 2026