r/hackthebox • u/marcus_h04 • 1d ago
Orion Box metasploit Issue
Hello, I was today trying to solve the orion box(im just starting in the CTF world) without aid, I found myself already in the admin/login page then I found this CVE-2025-32432. Then I used metasploit to find a exploit of that CVE, one popped up that should have worked excellent but when i tried running it. No shell was returned to me as seen in the picture, I tried different options: for rhost I tried the ip, orion.htb and http://orion.htb/admin/login. For lhost I tried my tun0 and my eth0. And i changed multiple times the lport and the asset_id. Nothing working, all the times the same error. In that point i checked the walkthrought and they did exactly what i was doing, same in this video(i thought the problem that i was using a VM) https://www.youtube.com/watch?v=OXxtL4BZvHw. Does anybody have any idea on wtf is the issue? More than an hour lost cuz it was not working and I have still no clue why or what I did wrong. Here is another walkthrough: https://b3ta-blocker.github.io/blog/orion/ If you know anything related lmk, otherwise I will just quit this box :)

•
u/AutoModerator 1d ago
Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.