RondoDox Botnet Targets HPE OneView Vulnerability in Exploitation Wave
ID: eb13cb0a-d133-5b38-b9fc-75a709a09835
STIX ID: report--eb13cb0a-d133-5b38-b9fc-75a709a09835
Feed Name: Infosecurity Magazine (News)
Threat Score
Check Point Research observed a large-scale, automated exploitation campaign by the Linux RondoDox botnet targeting a critical HPE OneView RCE (CVE-2025-37164, CVSS 3.1 score 10). The vulnerability in the ExecuteCommand REST API allows unauthenticated remote code execution; tens of thousands of exploitation attempts were blocked, the issue was reported to CISA and added to the KEV catalog, and organizations are urged to patch and apply mitigations immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
