Skip to main content
EPSS 99.9%top 0.03%

CVE-2025-24813: CWE-44 Path Equivalence: 'file.name' (Internal Dot) in Apache Software Foundation Apache Tomcat

0
Critical
Published: 08/03/2026 (08/03/2026, 09:40:19 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Tomcat

Description

China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.

CVSS v3.1

Score 10.0critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected software

Apache Software Foundation

Apache Tomcat

Affected versions
>=11.0.0-M1 <=11.0.2>=10.1.0-M1 <=10.1.34>=9.0.0.M1 <=9.0.98>=8.5.0 <=8.5.100
org.apache.tomcat/tomcat
pkg:maven/org.apache.tomcat/tomcat
Affected versions
=11.0.0-M1=10.1.0-M1=8.5.0>=8.5.0 <=8.5.100

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 12:37:47 UTC

Technical Analysis

This vulnerability arises from a path equivalence issue involving internal dots in file names ('file.name') processed by the write-enabled default servlet in Apache Tomcat. When partial PUT support is enabled (default setting), and certain conditions are met—such as a target URL for sensitive uploads being a subdirectory of public uploads, knowledge of sensitive file names by an attacker, and use of Tomcat's file-based session persistence with default storage—an attacker can view or inject malicious content into sensitive files. Additionally, if the application includes a library vulnerable to deserialization attacks, remote code execution is possible. The flaw affects multiple Tomcat versions including 11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, 9.0.0-M1 to 9.0.98, and certain EOL versions like 8.5.0 to 8.5.100. The issue is resolved in versions 11.0.3, 10.1.35, and 9.0.99.

Potential Impact

Successful exploitation can lead to remote code execution, allowing an attacker to execute arbitrary code on the server. It can also result in information disclosure or injection of malicious content into uploaded files. The vulnerability requires specific conditions such as write-enabled default servlet, partial PUT enabled, and knowledge of sensitive file names. The CVSS score of 10.0 reflects the critical nature and ease of exploitation without privileges or user interaction.

Mitigation Recommendations

Users should upgrade affected Apache Tomcat versions to 11.0.3, 10.1.35, or 9.0.99, which contain the official fix for this vulnerability. Until upgraded, disabling write access for the default servlet and/or disabling partial PUT support can mitigate the risk. Review application configurations to avoid using default file-based session persistence if vulnerable libraries are present. Patch status is confirmed fixed in the specified versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
apache
Date Reserved
2025-01-24T08:51:50.296Z
Cvss Version
3.1
State
PUBLISHED

Indicators of Compromise

Ip

ValueDescriptionCopy
ip221.198.83.248
ip149.129.37.105
ip92.38.135.196
ip130.94.30.168
ip130.94.17.180

Cve

ValueDescriptionCopy
cveCVE-2025-24813

Url

ValueDescriptionCopy
urlhttp://139.0.0.0
urlhttp://130.94.30.168:8080
urlhttp://149.129.37.105:30005
urlhttp://92.38.135.196:8888

Hash

ValueDescriptionCopy
hashd7ed70cdd88f6cccbdc0ad6851d7a61b7fce79fdf9c4cd9f9bb375233a96b2dd
hash456233b58bcf8c17ef9ef44b14a966a6
hash71072a8c4adfcde49a4b163959a24283
hash8887c65035893d99996991282553fc19
hash913a572c1bf9da27ee7d21befa3cee0c
hash9ab45387111475d5cfb77fb4e49eba82bad7ca4d
hasha24b4bb466324459f40e6adbc5d481ec6cee48ef
hashb1f71014f4c0e1e61c0b3fe2391a6c6aa03ac3f9
hashd26f84a768062c52179216bf6ca4c551448890be
hash00b0cef237d9619c99c5d90cf902ec768c1ecf4f96d542d31dc5afb0b564cb4f
hash20e1ec6b07abe3b2dd54f7ae4e47dc00afa46de6e6c0ef0239c26c8bae70a43a
hash2ac6c953d2d36eb7e7e85aa0822a65961071f7801a25118ab42bcfa9693327a1
hash4738f3559c10f7c62a3be48ec2ce42c584b53d5ffa9e06e6521607a6fdfd535f
hash66543c4f9f4d610a79efa5e52b9aa90ca41dbfc154418435a2902ac48dad2ee4
hash75d39860a5c5ce6c26590265102f25c50f91a22b6769d22046759fb3aff8d0a8
hash9c59a0dadec1f1b73724f3ee4113e4fde696214371b9068fd69774db4cd8b8d2
hasha4989ae1d598e79a87a9e01d0b5966a25b00b23ca234fbdb52b9df7b29db918a
hashadde431d5b78b2b2cfb67c5bcd938be6cc466fbb3ac2786cad97b493f6fcfad5
hashb272e2e4a7c65f2659a8fff8ceec4d9538f74f6dc9bace7d051a4476ba6bc77c
hashb7486bb7fc5f7e659b40dab3366b576d68db61ca0004de7a1e115eb9b541f19a
hashb96cdf8bc96c7288af7624974b1a10b7bf16e5ac03ac8493ade20696a906a81a
hashc0a5374a425ee5030b2219520dfa3a3a51f27d3cc4404b016e695c4450fe3034
hashc2d0e4dd2f2b3f1d4eb4518984b00ed521c73d1e935780786479db690112ef9c
hashdc493eb8367b7d68f4d3d9f2a10c495c6a45c33df72fb5a18bdf62b629f69e31
hashebc94e24e4df94f988dd0a2275e8a3f1957051814a3c39ec30bfaca2f5ca2607

Domain

ValueDescriptionCopy
domaingoogle.chromeupgrades.com
domainspeedtest.qqmail.website

Threat ID: 687e795da83201eaac11f328

Added to database: 07/21/2025, 17:31:09 UTC

Last enriched: 08/04/2026, 12:37:47 UTC

Last updated: 09/17/2026, 22:01:29 UTC

Views: 354

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses