Thehackernews
RondoDox Botnet Expands by Exploiting Unpatched XWiki RCE Vulnerability
First seen 17 Nov 2025, 09:55 UTC
•

•88% similarity
•69.8
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable, allowing RondoDox to infect additional devices and expand its network. The attack targets unpatched XWiki servers, increasing the botnet's reach.
ThreatCluster AI