logo

Trimble Cityworks: CVE-2025-0994

ID: eebdd2a1-c8f1-5ad2-9ea3-d9be50774c7f

STIX ID: report--eebdd2a1-c8f1-5ad2-9ea3-d9be50774c7f

Feed Name: Recorded Future Blog

Threat Score
80/100

Date Published: 2025-02-19

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group details CVE-2025-0994, a high-severity deserialization vulnerability in Trimble Cityworks that allows authenticated remote code execution against IIS. The report notes active exploitation delivering Rust-based loaders, VShell and Cobalt Strike, provides IoCs (including C2 IPs), cites 111 exposed Cityworks instances with a portion vulnerable, and recommends immediate patching to versions 15.8.9/23.10 or later with reference to CISA guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.