ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-24016CVE-2025-33053

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24016
Deserialization RCE in Wazuh Server (CVE-2025-24016)

Wazuh Server, the core component of the free and open-source Wazuh threat prevention, detection, and response platform, contains an unsafe deserialization flaw (CWE-502) affecting versions 4.4.0 through all releases prior to 4.9.1. DistributedAPI (DAPI) parameters are serialized as JSON and deserialized by the `as_wazuh_object` function in `framework/wazuh/core/cluster/common.py`; an attacker who injects an unsanitized dictionary into a DAPI request or response can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary Python code, yielding remote code execution on the server. The flaw is rated critical (CVSS 3.1: 9.9) and can be triggered by anyone with API access, such as a compromised dashboard or another Wazuh server in the cluster, and in certain configurations even by a compromised agent. All deployments of Wazuh Server running affected 4.4.x through 4.9.0 versions are affected, particularly those with the API or dashboard exposed to untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-06-10, and Akamai reported that two distinct Mirai botnets are actively targeting unpatched, internet-exposed Wazuh servers.

Do: Upgrade Wazuh to version 4.9.1 or later immediately, as required for federal systems under CISA KEV/BOD 22-01 guidance. Until patched, restrict internet exposure of the Wazuh API, dashboard, and cluster communications, and assume compromised agents may be a trigger path in affected configurations. Hunt unpatched servers for signs of compromise, since Mirai botnets are actively scanning for and exploiting this flaw.

9.994% KEV PoC
  • Wazuh Server >= 4.4.0 and < 4.9.1 (fixed in 4.9.1)
largetens of thousands of internet-exposed Wazuh servers, with total deployments (including internal-only clusters) likely in the hundreds of thousands (estimate)
CVE-2025-33053
Remote Code Execution in Microsoft Windows Internet Shortcut Files (CVE-2025-33053)

CVE-2025-33053 is an external control of file name or path flaw (CWE-73) in how Windows processes Internet Shortcut (.url) files, allowing an unauthorized attacker to execute code over a network by making the shortcut resolve to an attacker-controlled path, such as a WebDAV share. Exploitation requires user interaction (CVSS vector UI:R): a user opening a crafted .url file, typically delivered via phishing, causes Windows to fetch and run content from the attacker-specified location, yielding remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). All supported Windows 10 and Windows 11 client versions and Windows Server 2008, 2012, 2016, and 2019 are affected. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-10, Microsoft patched it in the June 2025 Patch Tuesday release, and Check Point research tied it to a cyber-espionage campaign by the Stealth Falcon actor against a major Turkish defense organization. EPSS estimates an 85.4% probability of exploitation within 30 days (100th percentile).

Do: Apply Microsoft's June 2025 security updates to all affected Windows 10/11 clients and Windows Server 2008/2012/2016/2019 hosts, consistent with the KEV required action and BOD 22-01 timelines for federal agencies. Until patched, consider disabling the Windows WebDAV client where it is not needed and treat unsolicited .url shortcut files as untrusted; given confirmed espionage use, hunt for signs of exploitation on high-value endpoints.

8.888% KEV PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ Windows devices (all listed Windows 10/11 client and mainstream Windows Server releases are affected)

Indicators of compromiseAll →

TypeIndicatorContext
domainduckdns.orgltiple architectures and link to C2 domains like nuklearcnc.duckdns[.]org and galaxias[.]cc. Other samples (e.g., “neon,” “k03ldc”)
domaingalaxias.cces and link to C2 domains like nuklearcnc.duckdns[.]org and galaxias[.]cc. Other samples (e.g., “neon,” “k03ldc”) showed ties to V3
domaingestisciweb.comoT architectures. It uses domains with Italian names (e.g., gestisciweb.com), suggesting a focus on Italian-speaking victims. The malwa
Full article618 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Wazuh, and WebDAV flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added ASUS RT-AX55 devices, Craft CMS, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-24016 (CVSS score 9.9) Wazuh Server Deserialization of Untrusted Data Vulnerability
  • CVE-2025-33053 (CVSS score 8.8) Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

This week, Akamai researchers warned that multiple Mirai botnets exploit the critical remote code execution vulnerability CVE-2025-24016 (CVSS score of 9.9) affecting Wazuh servers.

Wazuh is an open-source security platform used for threat detection, intrusion detection, log data analysis, and compliance monitoring. Organizations commonly deploy it to monitor endpoints and infrastructure for suspicious or malicious activity.

“Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code.” reads the advisory. “The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix.”

Researchers are aware of a PoC code to exploit this issue for arbitrary code execution.

Akamai SIRT observed active exploitation of CVE-2025-24016 RCE flaw via DAPI request abuse. The researchers reported that two Mirai botnet variants, including “Resbot” (featuring Italian domain names), have been exploiting the bug since March 2025. This marks the first known active abuse since its February disclosure.

“We observed two campaigns of Mirai variants exploiting this vulnerability.” reads the report published by Akamai. “One of these, “Resbot,” has Italian nomenclature involved in its domains, possibly alluding to the targeted geography or language spoken by the affected device owner.”

In March 2025, attackers exploited CVE-2025-24016 in Wazuh servers using a shell script to deploy the first variant of Mirai spotted by Akamai, mainly LZRD, across IoT devices. These samples, named “morte,” support multiple architectures and link to C2 domains like nuklearcnc.duckdns[.]org and galaxias[.]cc. Other samples (e.g., “neon,” “k03ldc”) showed ties to V3G4 and LZRD variants with unique console strings. The botnet also exploited other vulnerabilities, including Hadoop YARN, TP-Link AX21, and ZTE routers, using dynamic infrastructure to evade detection and spread rapidly.

In May 2025, a second botnet exploited the Wazuh endpoint using a shell script to deploy “resgod,” a Mirai variant with the string “Resentual got you!” Like the first variant, it targets multiple IoT architectures. It uses domains with Italian names (e.g., gestisciweb.com), suggesting a focus on Italian-speaking victims. The malware communicates with 104.168.101[.]27 via TCP port 62627 and spreads via FTP and telnet. It exploits several RCEs, including in Huawei, Realtek, ZyXEL routers, using unencrypted strings and broad scanning capabilities for rapid propagation.

Akamai published indicators of compromise (IoC) to detect the Mirai botnet variants

CVE-2025-33053 is an external file name or path control issue in WebDAV that lets unauthorized attackers execute code remotely over a network.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by July 1st, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178923/security/u-s-cisa-adds-wazuh-and-webdav-flaws-to-its-known-exploited-vulnerabilities-catalog.html