CVE-2018-25117P1CRITICALCVSS 9.3Exploited≥ a3f0fa1501d424477786e3e7150bb05c0b99518f, < ee03eff016e03cb76fac7ae3a0f9d1ef0f8ee35b2025-10-15
CVE-2018-25117 [CRITICAL] CWE-506 CVE-2018-25117: VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious cod
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a multi-stage DDoS bot that uses Lua for second- and third-stage compone
nvd