RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution.
The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request to the “/bin/get/Main/

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Post

Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies

Next Post

Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time

Related Posts
Total
0
Share