CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing

CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing

Published 20 Aug 2026Updated 20 Aug 202614 sources
CVSS 0.0 PoC CANDIDATE

What happened

A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
PoC-in-GitHub · lukasz-rybak/CVE-2025-69212CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing★ 4lukasz-rybak2026-04-11CandidatePoC-in-GitHub · tohib09/CVE-2025-69212-PoC★ 4tohib092026-06-27CandidatePoC-in-GitHub · c0gnit00/CVE-2026-69212Python poc, exploit for CVE-2025-69212★ 2c0gnit002026-06-28CandidatePoC-in-GitHub · w3nch/CVE-2025-69212★ 1w3nch2026-06-29CandidatePoC-in-GitHub · xorandd/CVE-2025-69212-PoC★ 0xorandd2026-06-30CandidatePoC-in-GitHub · BridgerAlderson/CVE-2025-69212-PoCOpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.★ 4BridgerAlderson2026-06-30CandidatePoC-in-GitHub · alaeddine03/CVE-2025-69212-PoCCVE-2025-69212 - OpenSTAManager OS Command Injection PoC★ 0alaeddine032026-07-01CandidatePoC-in-GitHub · m2sousa/CVE-2025-69212CVE-2025-69212 Proof-of-concept. Authenticated RCE in OpenSTAManager ≤2.9.8 via malicious ZIP uploads containing crafted .p7m filenames.★ 0m2sousa2026-07-01CandidatePoC-in-GitHub · 0Zetrium0/CVE-2025-69212_PoCThis repository contains a PoC exploit for CVE-2025-69212.★ 00Zetrium02026-07-03CandidatePoC-in-GitHub · mmoobbeeiidat-design/Hack-The-Box-Enigma-Findings-ReportHTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager (CVE-2025-69212) through to root via a misconfigured OliveTin service. Full report and evidence appendix to be published once permitted by HTB's active-machine policy.★ 0mmoobbeeiidat-design2026-07-12CandidatePoC-in-GitHub · liaomilk/CVE-2025-69212-for-myselfjust record for myself★ 0liaomilk2026-08-01CandidatePoC-in-GitHub · lolw0/OpenSTA-ExploitProof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing★ 0lolw02026-08-14CandidatePoC-in-GitHub · Pasindu-sd/CVE-2025-69212-ExploitA fully automated exploit script for **CVE-2025-69212**, a command injection vulnerability in OpenSTAManager. This script authenticates with admin credentials, deploys a malicious PHP web shell via a crafted P7M file in a ZIP archive, and provides command execution or a reverse shell.★ 0Pasindu-sd2026-08-21Candidate