Impact
emp3r0r is a Linux‑based C2 tool that uses an HTTP polling transport. Prior to version 4.2.5, the server accepts polling sessions before completing CBOR MsgAuth authentication. An unauthenticated attacker can create arbitrary sessions and send request bodies that are forwarded to the C2 dispatch path, consuming server resources and triggering pre‑authentication processing. This results in a Denial of Service. The weakness is resource exhaustion (CWE‑400).
Affected Systems
Emp3r0r C2 tool released by jm33‑m0. Versions prior to 4.2.5 are vulnerable. Version 4.2.5 and later contain the fix.
Risk and Exploitability
The CVSS score is 7.5, indicating a high‑severity vulnerability. The EPSS score is less than 1%, showing a low probability of exploitation in the current environment, and the issue is not listed in CISA KEV. An attacker can exploit the flaw remotely through unauthenticated HTTP traffic; no special privileges or pre‑existing access are required. Once an HTTP session is established, the attacker can flood the server with request bodies, exhausting CPU or memory and preventing legitimate clients from connecting.
OpenCVE Enrichment
Github GHSA