Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor

Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor

First seen 17 Jun 2026, 09:43 UTC Rapid7attackerkb.comcloud.google.comforums.ivanti.comlabs.watchtowr.com 88% similarity 80.7

Article Content

Browse articles
ThreatCluster

On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and evidence of exploitation was observed in mid-March 2025. Threat actor UNC5221, linked to China, successfully exploited the vulnerability, deploying new malware families TRAILBLAZE and BRUSHFIRE. The patch for this vulnerability was released on February 11, 2025, but the threat actor managed to reverse engineer it to exploit earlier versions. Ivanti and Mandiant have urged customers to upgrade their systems immediately to mitigate the risk. The incident highlights the ongoing threat posed by state-sponsored actors who can exploit vulnerabilities even after patches are issued.

Key Points: • CVE-2025-22457 allows unauthenticated remote code execution in Ivanti products. • Exploitation was confirmed by Mandiant, with evidence dating back to mid-March 2025. • Threat actor UNC5221, linked to China, deployed new malware following the exploit.

ThreatCluster AI How this analysis works

Timeline

2023-10-10
CVE-2023-4966 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-01-10
CVE-2023-46805 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2024-01-10
CVE-2024-21887 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2025-01-08
CVE-2025-0282 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-02-11
Patch released for CVE-2025-22457
Ivanti released a patch for the buffer overflow vulnerability in ICS 22.7R2.6.
cloud.google.com
2025-03-15
First exploitation observed
Evidence of active exploitation of CVE-2025-22457 was reported by Mandiant.
cloud.google.com
2025-04-03
CVE-2025-22457 disclosed
Ivanti published an advisory for the critical vulnerability affecting multiple products.
Rapid7
2025-04-04
CVE-2025-22457 added to CISA KEV
CVE-2025-22457 was added to the CISA Known Exploited Vulnerabilities catalog.
Date unknown
2025-04-08
First public PoC released
The first proof of concept for exploiting CVE-2025-22457 was made public.
Date unknown

Community

Browse all →