XWiki CVE-2025-24893 exploitation and miner deployment
Case score 63
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 63
- Main story score
- 63
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Vulnerability Active exploitation of XWiki CVE-2025-24893 with remote code execution and miner deployment. main
Overview
VulnCheck reports active exploitation of XWiki CVE-2025-24893
VulnCheck said attackers are actively exploiting XWiki CVE-2025-24893, an eval injection flaw that can allow arbitrary remote code execution through a request to the "/bin/get/Main/SolrSearch" endpoint. The observed abuse targeted XWiki canaries from an attacker geolocated in Vietnam and used a two-stage workflow: wget retrieved the downloader "x640" from "193.32.208[.]24:8080" and wrote it to "/tmp/11909", then follow-on payloads "x521" and "x522" fetched a cryptocurrency miner, killed competing miners such as XMRig and Kinsing, and launched the miner with a c3pool.org configuration.