CVE-2025-30007Hestiacp · Control_panel
Vulnerability data via NVD (ingested)
HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in is_dns_record_format_valid() combined with unsafe eval-based parsing in update_domain_zone() to prematurely close a variable assignment string and achieve full root code execution on the underlying host in a single DNS record creation step.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2025-30007product:"Hestiacp Control Panel"http.html:"Control Panel"More intel sources (5)
vuln:CVE-2025-30007vulnerabilities.cve_id: CVE-2025-30007CVE-2025-30007CVE-2025-30007"CVE-2025-30007" exploit -site:nvd.nist.gov