A particularly worrying hacking campaign is underway targeting the HPE OneView. According to Check Point Research, the Linux-based RondoDox is exploiting a vulnerability in HPE OneView, moving from simple system identification to massive, fully automated attacks.

From simple scans to mass exploitation
According to Check Point, initially, there were limited detection efforts, but within a few weeks the picture changed dramatically. The botnet began launching large-scale coordinated attacks, targeting organizations that had not had time to implement security updates.
Check Point warns that this development is a clear indication that attackers are now moving with automated tools, taking advantage of any delay in repairing critical systems.
See also: Backdoor LOTUSLITE targets US political entities
What is CVE-2025-37164 and why is it considered extremely dangerous?
The vulnerability at the center of the campaign has been documented as CVE-2025-37164. It was first published on the National Vulnerability Database (NVD) on December 16, 2025, and was rated by HPE itself with the maximum CVSS 3.1 severity score: 10.0.

This is a remote code execution (RCE) vulnerability, which allows an unauthorized attacker to execute arbitrary commands on the target system, without prior authentication.
Tens of thousands of attempts in a few hours
In an update on January 15, Check Point revealed that it has already blocked tens of thousands of exploitation attempts. The scale of the attack is indicative of the severity of the situation: on January 7 alone, between 05:45 and 09:20 UTC, more than 40,000 attempts were recorded specifically targeting CVE-2025-37164.
See also: StackWarp attack threatens confidential VMs on AMD
According to the researchers' analysis, all attacks bore the hallmarks of automated botnet activity, with common patterns and a pace that could not be achieved manually.
The RondoDox botnet and its history
RondoDox first became known to the general public in mid-2025 and has since been linked to exploiting high-profile vulnerabilities. Check Point reports that the botnet has also targeted other critical vulnerabilities, such as React2Shell (CVE-2025-55182) in December, primarily targeting edge and perimeter infrastructure that remains unpatched.
RondoDox's strategy clearly shows that attackers are looking for critical systems that are exposed online but not adequately shielded.
What is HPE OneView and why is it an attractive target?
HPE OneView is a widely used IT infrastructure managementthat automates the control of storage and networking resources. It is used by organizations in critical sectors, from enterprises to public services, which significantly increases its value as a target.

The vulnerability is located in the exposed REST API endpoint ExecuteCommand, which is related to the id-pools functionality. The endpoint accepts data directly from the attacker and executes it on the operating system without any authentication or authorization checks — an extremely dangerous design flaw.
See also: Google Fast Pair: Vulnerabilities allow attackers to track you
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What organizations should do immediately
Experts are clear: organizations using HPE OneView should immediately apply available updates security and ensure that countermeasures are in place, such as restricting access to vulnerable endpoints.
As Check Point points out, active exploitation of the vulnerability makes any delay potentially catastrophic. In an environment where botnets operate with speed and automation, timely response is not just good practice — it’s a necessity.
