blog.chebuya.com
https://blog.chebuya.com/posts/unauthenticated-remote-command-execution-on-byob CVE-2024-45257
HIGH
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
Record summary
CVE-2024-45257 has a selected CVSS score of 7.3 (high); EIP currently links 1 catalogued exploit.
Description
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2026 · Source: CVE List
Proofs of concept
1Catalogued exploits
MetasploitBYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)Metasploit exploitby Valentin Lobstein +1 moreNot analyzed1 file
References
4github.com
https://github.com/malwaredllc/byob nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45257 raw.githubusercontent.com
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/byob_unauth_rce.rb