CVE-2025-12548
CRITICAL EXPLOITEDEclipse Che che-machine-exec - Unauthenticated Remote Command Execution
Title source: manualExploitation Summary
CVE-2025-12548 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit from researchers including Richard Leach, Greg Durys <[email protected]>, including a Metasploit module exploits/linux/http/eclipse_che_machine_exec_rce.
AI-analyzed exploit summary This Metasploit module exploits CVE-2025-12548, an unauthenticated RCE in Eclipse Che's machine-exec service via WebSocket JSON-RPC commands. It connects to port 3333, stages a payload, and executes arbitrary commands without authentication.
Description
A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.
Exploits (1)
This Metasploit module exploits CVE-2025-12548, an unauthenticated RCE in Eclipse Che's machine-exec service via WebSocket JSON-RPC commands. It connects to port 3333, stages a payload, and executes arbitrary commands without authentication.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H