CVE-2025-24813: CWE-44 Path Equivalence: 'file.name' (Internal Dot) in Apache Software Foundation Apache Tomcat
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
AI Analysis
Technical Summary
This vulnerability arises from a path equivalence issue involving internal dots in file names ('file.name') processed by the write-enabled default servlet in Apache Tomcat. When partial PUT support is enabled (default setting), and certain conditions are met—such as a target URL for sensitive uploads being a subdirectory of public uploads, knowledge of sensitive file names by an attacker, and use of Tomcat's file-based session persistence with default storage—an attacker can view or inject malicious content into sensitive files. Additionally, if the application includes a library vulnerable to deserialization attacks, remote code execution is possible. The flaw affects multiple Tomcat versions including 11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, 9.0.0-M1 to 9.0.98, and certain EOL versions like 8.5.0 to 8.5.100. The issue is resolved in versions 11.0.3, 10.1.35, and 9.0.99.
Potential Impact
Successful exploitation can lead to remote code execution, allowing an attacker to execute arbitrary code on the server. It can also result in information disclosure or injection of malicious content into uploaded files. The vulnerability requires specific conditions such as write-enabled default servlet, partial PUT enabled, and knowledge of sensitive file names. The CVSS score of 10.0 reflects the critical nature and ease of exploitation without privileges or user interaction.
Mitigation Recommendations
Users should upgrade affected Apache Tomcat versions to 11.0.3, 10.1.35, or 9.0.99, which contain the official fix for this vulnerability. Until upgraded, disabling write access for the default servlet and/or disabling partial PUT support can mitigate the risk. Review application configurations to avoid using default file-based session persistence if vulnerable libraries are present. Patch status is confirmed fixed in the specified versions.
Indicators of Compromise
- ip: 221.198.83.248
- ip: 149.129.37.105
- ip: 92.38.135.196
- cve: CVE-2025-24813
- url: http://139.0.0.0
- ip: 130.94.30.168
- ip: 130.94.17.180
- hash: d7ed70cdd88f6cccbdc0ad6851d7a61b7fce79fdf9c4cd9f9bb375233a96b2dd
- hash: 456233b58bcf8c17ef9ef44b14a966a6
- hash: 71072a8c4adfcde49a4b163959a24283
- hash: 8887c65035893d99996991282553fc19
- hash: 913a572c1bf9da27ee7d21befa3cee0c
- hash: 9ab45387111475d5cfb77fb4e49eba82bad7ca4d
- hash: a24b4bb466324459f40e6adbc5d481ec6cee48ef
- hash: b1f71014f4c0e1e61c0b3fe2391a6c6aa03ac3f9
- hash: d26f84a768062c52179216bf6ca4c551448890be
- hash: 00b0cef237d9619c99c5d90cf902ec768c1ecf4f96d542d31dc5afb0b564cb4f
- hash: 20e1ec6b07abe3b2dd54f7ae4e47dc00afa46de6e6c0ef0239c26c8bae70a43a
- hash: 2ac6c953d2d36eb7e7e85aa0822a65961071f7801a25118ab42bcfa9693327a1
- hash: 4738f3559c10f7c62a3be48ec2ce42c584b53d5ffa9e06e6521607a6fdfd535f
- hash: 66543c4f9f4d610a79efa5e52b9aa90ca41dbfc154418435a2902ac48dad2ee4
- hash: 75d39860a5c5ce6c26590265102f25c50f91a22b6769d22046759fb3aff8d0a8
- hash: 9c59a0dadec1f1b73724f3ee4113e4fde696214371b9068fd69774db4cd8b8d2
- hash: a4989ae1d598e79a87a9e01d0b5966a25b00b23ca234fbdb52b9df7b29db918a
- hash: adde431d5b78b2b2cfb67c5bcd938be6cc466fbb3ac2786cad97b493f6fcfad5
- hash: b272e2e4a7c65f2659a8fff8ceec4d9538f74f6dc9bace7d051a4476ba6bc77c
- hash: b7486bb7fc5f7e659b40dab3366b576d68db61ca0004de7a1e115eb9b541f19a
- hash: b96cdf8bc96c7288af7624974b1a10b7bf16e5ac03ac8493ade20696a906a81a
- hash: c0a5374a425ee5030b2219520dfa3a3a51f27d3cc4404b016e695c4450fe3034
- hash: c2d0e4dd2f2b3f1d4eb4518984b00ed521c73d1e935780786479db690112ef9c
- hash: dc493eb8367b7d68f4d3d9f2a10c495c6a45c33df72fb5a18bdf62b629f69e31
- hash: ebc94e24e4df94f988dd0a2275e8a3f1957051814a3c39ec30bfaca2f5ca2607
- url: http://130.94.30.168:8080
- url: http://149.129.37.105:30005
- url: http://92.38.135.196:8888
- domain: google.chromeupgrades.com
- domain: speedtest.qqmail.website
CVE-2025-24813: CWE-44 Path Equivalence: 'file.name' (Internal Dot) in Apache Software Foundation Apache Tomcat
Description
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
CVSS v3.1
Score 10.0critical
Affected software
Apache Software Foundation
Apache Tomcat
pkg:maven/org.apache.tomcat/tomcatRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from a path equivalence issue involving internal dots in file names ('file.name') processed by the write-enabled default servlet in Apache Tomcat. When partial PUT support is enabled (default setting), and certain conditions are met—such as a target URL for sensitive uploads being a subdirectory of public uploads, knowledge of sensitive file names by an attacker, and use of Tomcat's file-based session persistence with default storage—an attacker can view or inject malicious content into sensitive files. Additionally, if the application includes a library vulnerable to deserialization attacks, remote code execution is possible. The flaw affects multiple Tomcat versions including 11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, 9.0.0-M1 to 9.0.98, and certain EOL versions like 8.5.0 to 8.5.100. The issue is resolved in versions 11.0.3, 10.1.35, and 9.0.99.
Potential Impact
Successful exploitation can lead to remote code execution, allowing an attacker to execute arbitrary code on the server. It can also result in information disclosure or injection of malicious content into uploaded files. The vulnerability requires specific conditions such as write-enabled default servlet, partial PUT enabled, and knowledge of sensitive file names. The CVSS score of 10.0 reflects the critical nature and ease of exploitation without privileges or user interaction.
Mitigation Recommendations
Users should upgrade affected Apache Tomcat versions to 11.0.3, 10.1.35, or 9.0.99, which contain the official fix for this vulnerability. Until upgraded, disabling write access for the default servlet and/or disabling partial PUT support can mitigate the risk. Review application configurations to avoid using default file-based session persistence if vulnerable libraries are present. Patch status is confirmed fixed in the specified versions.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- apache
- Date Reserved
- 2025-01-24T08:51:50.296Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip221.198.83.248 | — | |
ip149.129.37.105 | — | |
ip92.38.135.196 | — | |
ip130.94.30.168 | — | |
ip130.94.17.180 | — |
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2025-24813 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://139.0.0.0 | — | |
urlhttp://130.94.30.168:8080 | — | |
urlhttp://149.129.37.105:30005 | — | |
urlhttp://92.38.135.196:8888 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashd7ed70cdd88f6cccbdc0ad6851d7a61b7fce79fdf9c4cd9f9bb375233a96b2dd | — | |
hash456233b58bcf8c17ef9ef44b14a966a6 | — | |
hash71072a8c4adfcde49a4b163959a24283 | — | |
hash8887c65035893d99996991282553fc19 | — | |
hash913a572c1bf9da27ee7d21befa3cee0c | — | |
hash9ab45387111475d5cfb77fb4e49eba82bad7ca4d | — | |
hasha24b4bb466324459f40e6adbc5d481ec6cee48ef | — | |
hashb1f71014f4c0e1e61c0b3fe2391a6c6aa03ac3f9 | — | |
hashd26f84a768062c52179216bf6ca4c551448890be | — | |
hash00b0cef237d9619c99c5d90cf902ec768c1ecf4f96d542d31dc5afb0b564cb4f | — | |
hash20e1ec6b07abe3b2dd54f7ae4e47dc00afa46de6e6c0ef0239c26c8bae70a43a | — | |
hash2ac6c953d2d36eb7e7e85aa0822a65961071f7801a25118ab42bcfa9693327a1 | — | |
hash4738f3559c10f7c62a3be48ec2ce42c584b53d5ffa9e06e6521607a6fdfd535f | — | |
hash66543c4f9f4d610a79efa5e52b9aa90ca41dbfc154418435a2902ac48dad2ee4 | — | |
hash75d39860a5c5ce6c26590265102f25c50f91a22b6769d22046759fb3aff8d0a8 | — | |
hash9c59a0dadec1f1b73724f3ee4113e4fde696214371b9068fd69774db4cd8b8d2 | — | |
hasha4989ae1d598e79a87a9e01d0b5966a25b00b23ca234fbdb52b9df7b29db918a | — | |
hashadde431d5b78b2b2cfb67c5bcd938be6cc466fbb3ac2786cad97b493f6fcfad5 | — | |
hashb272e2e4a7c65f2659a8fff8ceec4d9538f74f6dc9bace7d051a4476ba6bc77c | — | |
hashb7486bb7fc5f7e659b40dab3366b576d68db61ca0004de7a1e115eb9b541f19a | — | |
hashb96cdf8bc96c7288af7624974b1a10b7bf16e5ac03ac8493ade20696a906a81a | — | |
hashc0a5374a425ee5030b2219520dfa3a3a51f27d3cc4404b016e695c4450fe3034 | — | |
hashc2d0e4dd2f2b3f1d4eb4518984b00ed521c73d1e935780786479db690112ef9c | — | |
hashdc493eb8367b7d68f4d3d9f2a10c495c6a45c33df72fb5a18bdf62b629f69e31 | — | |
hashebc94e24e4df94f988dd0a2275e8a3f1957051814a3c39ec30bfaca2f5ca2607 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaingoogle.chromeupgrades.com | — | |
domainspeedtest.qqmail.website | — |
Threat ID: 687e795da83201eaac11f328
Added to database: 07/21/2025, 17:31:09 UTC
Last enriched: 08/04/2026, 12:37:47 UTC
Last updated: 09/17/2026, 22:01:29 UTC
Views: 354
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.