Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-25117

29
FAUCET Score

CVE-2018-25117 describes a supply-chain compromise in VestaCP installer commits from May to June 2018, embedding malicious code that affected new installations. This critical vulnerability (CVSS 9.3) allowed for the installation of the Linux/ChachaDDoS bot, exfiltration of administrative credentials, and execution of DDoS malware under local system privileges. The attack required user interaction (UI:A) to install the compromised software, leading to severe impacts on confidentiality, integrity, and availability. While Vesta acknowledged exploitation in October 2018, there is no public exploit code, Metasploit module, or significant community discussion, and it is not listed on the KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
VestaControl Panel (CP)
>= a3f0fa1501d424477786e3e7150bb05c0b99518f, < ee03eff016e03cb76fac7ae3a0f9d1ef0f8ee35bCNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 38th percentile among its peer group of 836 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

forum.vestacp.com / viewtopic.php
forum.vestacp.com / viewtopic.php
github.com / outroll/vesta
github.com / outroll/vesta/commit/a3f0fa1501d424477786e3e7150bb05c0b99518f
github.com / outroll/vesta/commit/ee03eff016e03cb76fac7ae3a0f9d1ef0f8ee35b
vestacp.com
vulncheck.com / advisories/vestacp-debian-installer-malicious-backdoor-supply-chain-compromise
welivesecurity.com / 2018/10/18/new-linux-chachaddos-malware-distributed-servers-vestacp-installed