nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-34061 CVE-2025-34061
CRITICAL
PHPStudy 2016-2018 Backdoor Remote Code Execution Vulnerability
Record summary
CVE-2025-34061 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded PHP payloads in the Accept-Charset HTTP header of incoming requests, decodes and executes the payload without proper validation. This leads to remote code execution as the web server user, compromising the affected system.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 7, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 2016 to ≤ 2018 | affected |
Proofs of concept
1Catalogued exploits
MetasploitPHPStudy Backdoor Remote Code executionMetasploit exploitby Airevan +1 moreNot analyzed1 file
References
3raw.githubusercontent.comexploit
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/phpstudy_backdoor_rce.rb xp.cnproduct
https://www.xp.cn/phpstudy