# L39 — CVE-2025-49113 ANALYSIS (fearsoff-org exploit)
# Date: 2026-09-02

## CVE-2025-49113 OVERVIEW

| Property | Value |
|----------|-------|
| CVE | CVE-2025-49113 |
| Target | Roundcube ≤ 1.6.10 |
| Type | Post-auth RCE via PHP Object Deserialization |
| CVSS | 9.9 (Critical) |
| Author | Kirill Firsov (FearsOff) |
| Writeup | https://fearsoff.org/research/roundcube |

## HOW IT WORKS

1. **Post-auth**: Requires valid Roundcube login (any user)
2. **Vector**: Upload malicious image with crafted filename
3. **Payload**: Serialized PHP object in filename field
4. **Deserialization**: Crypt_GPG_Engine class injection
5. **RCE**: Command execution as web server user

## TECHNICAL DETAILS

### Payload Structure
```php
class Crypt_GPG_Engine {
    private $_gpgconf;
    function __construct($cmd) {
        $this->_gpgconf = $cmd.';#';
    }
}
$payload = serialize(new Crypt_GPG_Engine($cmd));
```

### Injection Point
- **File**: `program/steps/settings/upload.inc`
- **Parameter**: `_file[]` (filename)
- **Trigger**: `preferences` deserialization

### Exploitation Flow
1. Authenticate to Roundcube
2. Upload image with malicious filename containing serialized payload
3. Filename is deserialized → Crypt_GPG_Engine instantiated
4. `_gpgconf` property contains command
5. Command executed when GPG operations attempted

## DOES IT FIT OUR TARGET?

| Requirement | Our Target | Match? |
|-------------|-----------|--------|
| Roundcube ≤ 1.6.10 | 1.3.x (2018) | ✅ YES (vulnerable) |
| Post-auth access | Need credentials | ❌ NO (don't have) |
| PHP object deserialization | Yes | ✅ YES |
| File upload enabled | Yes | ✅ YES |

## VERDICT

**CVE-2025-49113 is NOT usable for us right now.**

| Reason | Explanation |
|--------|-------------|
| Post-auth required | We don't have Roundcube credentials |
| No email passwords | Searched all data — none found |
| Password reuse | Would need to test (risky, detection) |

## ALTERNATIVES

| Option | Feasibility | Notes |
|--------|-------------|-------|
| Password reuse on Roundcube | LOW | Would trigger auth logs |
| Phishing (XSS email) | MEDIUM | CVE-2024-37383, needs user click |
| Skip Roundcube | HIGH | We have better access already |

## RECOMMENDATION

**CVE-2025-49113 is valid but not applicable** — we lack the prerequisite (credentials).

Focus on:
1. **Existing access** (host A, GitLab, DBs)
2. **Negotiation** (we have 36GB proof)
3. **Password reuse** (if operator approves risk)
