HomeSecurityRondoDox exploits vulnerable XWiki servers

RondoDox exploits vulnerable XWiki servers

The RondoDox targets the XWiki, exploiting a critical security vulnerability that could allow attackers to achieve arbitrary code execution.

RondoDox XWiki

The vulnerability is tracked as CVE-2025-24893 (CVSS score: 9.8) and is an eval injection bug, which could allow any guest user to execute code remotely via a request to the “/bin/get/Main/SolrSearch“ endpoint. The maintainers fixed the issue in XWiki versions 15.10.11, 16.4.1, and 16.5.0RC1 in late February 2025.

See also: Ethereum Wallet emerges as a serious threat

Although there were indications that the vulnerability had been exploited since March (at least), the issue gained attention in late October, when VulnCheck revealed that it had observed new attempts to exploit the vulnerability as part of a two-stage attack chain to deploy a cryptocurrency miner.

The U.S. Cybersecurity and Infrastructure Security Administration (CISA) then added the vulnerability to the Known Exploitable Vulnerabilities (KEV) list, requiring federal agencies to implement the necessary mitigations by November 20.

XWiki vulnerability: Multiple abuse attempts and RondoDox

In a new report published on Friday, VulnCheck revealed that it has since observed an increase in exploitation attempts, reaching a new high on November 7, followed by another increase on November 11. This suggests broader scanning activity, likely driven by multiple malicious actors participating in the effort.

See also: NVIDIA NeMo Framework vulnerabilities allow privilege escalation

RondoDox exploits vulnerable XWiki servers

This includes RondoDox, which rapidly adds new exploit channels to join vulnerable devices into a botnet to conduct attacks denial-of-service using the HTTP, UDP, and TCP protocols. The first RondoDox exploit was observed on November 3, 2025, according to the cybersecurity firm.

Other attacks have also been observed exploiting the vulnerability to deliver cryptocurrency miners, while attempts to install a reverse shell.

The findings once again highlight the need to adopt strong update management to ensure optimal protection.

See also: Attacks on AI Models – Model Inversion and Prompt Injection

RondoDox exploits vulnerable XWiki servers

“CVE-2025-24893 is a familiar story: one attacker moves first, and many follow,” said VulnCheck’s Jacob Baines. “Within days of the initial exploit, we saw botnets, miners, and opportunistic scanners abusing the same vulnerability.”

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS