HomeSecurityRediShell RCE Vulnerability: Over 8,500 Redis Vulnerable Instances

RediShell RCE Vulnerability: Over 8,500 Redis Vulnerable Instances

The cybersecurity landscape faced a critical threat in early October 2025 with the public disclosure of RediShell, a serious use-after-free vulnerability in Redis' Lua scripting engine.

See also: XWiki: RCE vulnerability used to deliver cryptominer

RediShell

Identified as CVE-2025-49844 and dubbed “RediShell” by Wiz researchers, this vulnerability allows attackers to bypass Lua sandbox restrictions and achieve remote host-level code execution on vulnerable systems. The vulnerability results from cumulative errors in the core Redis architecture, affecting installations dating back to 2012, when the vulnerable code path was initially introduced.

The attack surface immediately proved to be extensive and alarming. CriminalIP analysts identified over 8,500 Redis instances worldwide that remain vulnerable to exploitation as of October 27, 2025. These instances are immediately exposed to the public internet, creating a critical window of opportunity for malicious users using automated scanning techniques.

In environments where authentication mechanisms remain disabled—a surprisingly common setting for deployment and older installations—attackers can deliver malicious Lua scripts without any requirement for credentials, dramatically lowering the barrier to successful exploitation.

The global distribution of affected systems reveals worrying concentrations in specific regions. CriminalIP researchers noted that the United States hosts the largest number of vulnerable cases with 1,887 cases, followed by France with 1,324 and Germany with 929 cases, collectively representing over 50 percent of the total global exposure.

See also: Dolby Digital Plus: Vulnerability allows RCE attack

RediShell RCE Vulnerability: Over 8,500 Redis Vulnerable Instances

This geographic concentration suggests either deliberate targeting of specific infrastructure nodes or widespread adoption of unpatched Redis instances in enterprise environments in these regions.

The technical basis of RediShell focuses on manipulating Redis' garbage collection behavior through specially crafted Lua scripts. An attacker sends a malicious script that targets the use-after-free state, allowing the script to escape the confines of the Lua sandbox environment.

Once outside the sandbox, the script achieves arbitrary native code execution with the privileges of the Redis process. The exploitation sequence typically begins with the initial breach via malicious Lua delivery, followed by sandbox escape, installation of reverse shells or backdoors for persistent access, and subsequent credential theft to facilitate lateral movement throughout the infrastructure.

The vulnerability turns what appears to be a data caching service into a full-fledged entry point for host compromise. Organizations operating affected Redis instances without proper authentication or network isolation face an immediate risk of complete infrastructure takeover, data exfiltration, and deployment of secondary payloads such as cryptocurrency miners and ransomware.

Prompt updating remains an absolute priority. Organizations should immediately upgrade to updated versions of Redis as recommended in official security advisories. For environments where updating is experiencing delays, enabling authentication via AUTH or ACL settings, restricting network access to port 6379, and disabling Lua execution commands such as EVAL and EVALSHA provide intermediate levels of protection.

See also: Veeam Backup: Critical RCE vulnerabilities allow remote code execution

RediShell RCE Vulnerability: Over 8,500 Redis Vulnerable Instances

Continuous monitoring through threat intelligence platforms remains essential to detect both exposure and exploitation attempts across the entire infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS