PT-2025-6100 · Wazuh · Wazuh

Danielfi

·

Published

2025-02-10

·

Updated

2026-03-11

·

CVE-2025-24016

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wazuh versions 4.4.0 through 4.9.1
Description Wazuh, a platform used for threat prevention, detection, and response, is affected by an unsafe deserialization vulnerability. This flaw, potentially allowing remote code execution, arises from the insecure deserialization of DistributedAPI parameters using the as wazuh object function (located in framework/wazuh/core/cluster/common.py). An attacker can exploit this by injecting an unsanitized dictionary into a DAPI request or response, forging an unhandled exception (unhandled exc) to execute arbitrary Python code. The vulnerability can be triggered by anyone with API access, or in certain configurations, even a compromised agent. Multiple Mirai botnets are actively exploiting this vulnerability, leading to DDoS attacks. The /security/user/authenticate/run as API endpoint is a target for exploitation. The vulnerability is actively exploited in the wild.
Recommendations Upgrade Wazuh to version 4.9.1 or later. Restrict API access to trusted networks and enforce strict authentication. Regularly monitor logs for suspicious activity. Secure agent configurations to prevent exploitation from compromised endpoints.

Exploit

Fix

DoS

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-01366
CVE-2025-24016
GHSA-HCRC-79HJ-M3QH
GO-2025-3459
OPENSUSE-SU-2025:14889-1

Affected Products

Wazuh