CVE Database
/

CVE-2018-25117

Back to search

CVE-2018-25117

Published: Oct 15, 2025

Modified: Mar 23, 2026

PUBLISHED

Description

VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a multi-stage DDoS bot that uses Lua for second- and third-stage components. The compromise leaked administrative credentials (base64-encoded admin password and server domain) to an external URL during installation and/or resulted in the installer dropping and executing a DDoS malware payload under local system privileges. Compromised servers were subsequently observed participating in large-scale DDoS activity. Vesta acknowledged exploitation in the wild in October 2018.

VendorProductVersions

Vesta

Control Panel (CP)

affected
a3f0fa1501d424477786e3e7150bb05c0b99518f - < ee03eff016e03cb76fac7ae3a0f9d1ef0f8ee35b

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now