Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 21 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vestacp:control_panel:*:*:*:*:*:*:*:* |
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Vestacp Vestacp control Panel |
|
| Vendors & Products |
Linux
Linux linux Vestacp Vestacp control Panel |
Wed, 15 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a multi-stage DDoS bot that uses Lua for second- and third-stage components. The compromise leaked administrative credentials (base64-encoded admin password and server domain) to an external URL during installation and/or resulted in the installer dropping and executing a DDoS malware payload under local system privileges. Compromised servers were subsequently observed participating in large-scale DDoS activity. Vesta acknowledged exploitation in the wild in October 2018. | |
| Title | VestaCP Debian Installer Malicious Backdoor Supply Chain Compromise | |
| Weaknesses | CWE-506 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-23T15:43:25.125Z
Reserved: 2025-10-14T16:07:20.780Z
Link: CVE-2018-25117
Updated: 2025-10-15T18:55:54.828Z
Status : Deferred
Published: 2025-10-15T02:15:31.580
Modified: 2026-04-15T00:35:42.020
Link: CVE-2018-25117
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:41:17Z