logo

Hackers Use CVE-2024-50603 to Deploy Backdoor on Aviatrix Controllers

ID: 3e8e9d35-7f4a-565a-915e-bfe35b6f51e1

STIX ID: report--3e8e9d35-7f4a-565a-915e-bfe35b6f51e1

Feed Name: HackRead

Threat Score
90/100

Date Published: 2025-01-15

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Aviatrix Controller contains a critical command-injection vulnerability (CVE-2024-50603, CVSS 10.0) in its PHP API that allows unauthenticated remote code execution. Wiz Research has observed active exploitation in the wild where attackers install cryptocurrency miners and backdoors; affected versions are prior to 7.1.4191 and 7.2.4996. The report recommends immediate patching to the fixed releases and implementing network restrictions, proactive hunting for compromises, and log/event analysis to detect malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.