CVE-2025-52572

CRITICAL EXPLOITED

Hikka Telegram Userbot Web Interface - Account Takeover and Code Execution

Title source: manual
STIX 2.1

Exploitation Summary

CVE-2025-52572 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. Web interface does not have an authenticated session: attacker can use his own Telegram account to gain RCE to the server by authorizing in the dangling web interface. 2. Web interface does have an authenticated session: due to insufficient warning in the authentication message, users were tempted to click "Allow" in the "Allow web application ops" menu. This gave an attacker access not only to remote code execution, but also to Telegram accounts of owners. Scenario number 2 is known to have been exploited in the wild. No known patches are available, but some workarounds are available. Use `--no-web` flag and do not start userbot without it; after authorizing in the web interface, close the port on the server and/or start the userbot with `--no-web` flag; and do not click "Allow" in your helper bot unless it is your explicit action that needs to be allowed.

References (2)

Core 2
Core References
Various Sources x_refsource_misc
https://t.me/bbcode/9

Scores

CVSS v3 10.0
EPSS 0.0062
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2023-08-12
CWE
CWE-287
Status published
Products (1)
hikariatama/Hikka <= 1.7.0-wip
Published Jun 24, 2025
Tracked Since Feb 18, 2026