This module exploits CVE-2026-88771, a command injection vulnerability present in the ns_monuploadd_err.pl script of Citrix NetScaler ADC and Gateway to deploy a Core Impact Network agent that will run with root privileges. The module will exploit the vulnerability by sending a crafted HTTP POST request the /p/u/doAuthentication.do endpoint with the payload inside the User-Agent header. The result of the HTTP request will determine if the command injection was successful. If the command injection is successful, the module will wait up to 24 hours for agent connection. This is because the appliance runs the ns_monuploadd_err.pl script every 24 hours and the attack has no way to determine the current timelapse for this behaviour. The deployed Core Impact Network agent will run with root privileges.
CVE Link
Exploit Platform
Exploit Type
Product Name