RondoDox, a botnet malware, has been seen to target unpatched XWiki instances in order to exploit a serious security vulnerability that might enable attackers to execute arbitrary code.
CVE-2025-24893 (CVSS score: 9.8) is the vulnerability in question. It is an eval injection problem that might enable any guest user to execute arbitrary remote code by sending a request to the “.bin/get/Main/SolrSearch” endpoint. In late February 2025, the maintainers fixed it in XWiki 15.10.11, 16.4.1, and 16.5.0RC1.
It wasn’t until late October that VulnCheck said it had seen new attempts to weaponize the issue as part of a two-stage attack chain to deploy a bitcoin miner, despite indications that the vulnerability had been exploited in the wild since at least March.
The vulnerability was then added to the Known Exploited Vulnerabilities (KEV) database by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) read more about RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
