PT-2025-6100 · Wazuh · Wazuh
Danielfi
·
Published
2025-02-10
·
Updated
2026-03-11
·
CVE-2025-24016
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wazuh versions 4.4.0 through 4.9.1
Description
Wazuh, a platform used for threat prevention, detection, and response, is affected by an unsafe deserialization vulnerability. This flaw, potentially allowing remote code execution, arises from the insecure deserialization of DistributedAPI parameters using the
as wazuh object function (located in framework/wazuh/core/cluster/common.py). An attacker can exploit this by injecting an unsanitized dictionary into a DAPI request or response, forging an unhandled exception (unhandled exc) to execute arbitrary Python code. The vulnerability can be triggered by anyone with API access, or in certain configurations, even a compromised agent. Multiple Mirai botnets are actively exploiting this vulnerability, leading to DDoS attacks. The /security/user/authenticate/run as API endpoint is a target for exploitation. The vulnerability is actively exploited in the wild.Recommendations
Upgrade Wazuh to version 4.9.1 or later. Restrict API access to trusted networks and enforce strict authentication. Regularly monitor logs for suspicious activity. Secure agent configurations to prevent exploitation from compromised endpoints.
Exploit
Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wazuh