LogoAISecKit
  • Search
  • Collection
  • Category
  • Tag
  • Blog
  • Pricing
  • Submit
LogoAISecKit

Newsletter

Join the Community

Subscribe to our newsletter for the latest news and updates

LogoAISecKit

Curated directory of 1700+ AI tools, models, frameworks, MCP servers, and cybersecurity resources

GitHub
Product
  • Search
  • Collection
  • Category
  • Tag
Resources
  • Blog
  • Pricing
  • Submit
Company
  • About Us
  • Privacy Policy
  • Terms of Service
  • Sitemap
Copyright © 2026 All Rights Reserved.
Sponsored Resources
  1. Home
  2. Category
  3. CVE-2025-24016
icon of CVE-2025-24016

CVE-2025-24016

Demonstrates the CVE-2025-24016 RCE vulnerability in the Wazuh server.

Visit Website
image for CVE-2025-24016
Visit Website

Introduction

CVE-2025-24016: RCE in Wazuh Server

This repository demonstrates the remote code execution (RCE) vulnerability in the Wazuh server, introduced by unsafe deserialization in the wazuh-manager package. The vulnerability allows remote attackers with API access to execute arbitrary code on the server.

Key Features
  • Vulnerability Overview: Detailed discussion of the RCE vulnerability
  • Affected Versions: Information on which versions are impacted
  • Proof of Concept: A practical demonstration of the vulnerability
  • Mitigation Advice: Recommendations on how to protect systems by upgrading to patched versions
Benefits
  • Helps developers and security teams understand the risks associated with the Wazuh server.
  • Provides a method to test for vulnerabilities in current systems using a provided Proof of Concept.
Highlights
  • RCE triggered via the run_as endpoint in Wazuh API.
  • Explains the impact and how to reproduce the vulnerability effectively using specific conditions.
Back

Information

  • Publisher
    AISecKit
  • Websitegithub.com
  • Published date2025/04/28

Categories

  • Incident Response Tools
  • Penetration Testing
  • Vulnerability Disclosure

Tags

  • Application Security
  • Exploit Development
  • Security Auditing
  • Incident Response
  • Vulnerability Disclosure

More Products

image of Phantom
DevSecOps ToolsPenetration TestingVulnerability Scanners
Visit Website
icon of Phantom

Phantom

A browser extension for SRC vulnerability mining, collecting sensitive information and suspicious clues from web pages.

Security AuditingOpen SourceIncident ResponseVulnerability ScanningAPI Security+1
E
Penetration TestingSecurity Training PlatformsAI Security Monitoring
Visit Website
icon of Exploiting AI

Exploiting AI

An introductory class on understanding AI security risks and mitigation strategies.

Prompt InjectionGenerative AIRed Team TestingData Poisoning
F
Input Validation & FilteringPenetration TestingAI Security Monitoring
Visit Website
icon of Folly

Folly

Open-source LLM Prompt-Injection and Jailbreaking Playground for testing LLM security vulnerabilities.

Prompt InjectionOpen SourceAPI SecuritySecurity TestingLLM Security+1