Vulnerability CVE-2025-31324 (CVSS 10): Zero-Day in SAP NetWeaver Exploited in the Wild to Deploy Webshells and C2 Frameworks Do Son April 25, 2025 3 minutes read 0 Add as a preferredsource on Google π Access to This Vulnerability Report Requires Support This article is available to verified supporters only - contribute to read the full report Or choose another support option: Support via PayPal Support via BMC Share this article: Facebook Post LinkedIn Telegramcve-2025-31324-cvss-10-zero-day-in-sap-netweaver-exploited-in-the-wild-to-deploy-webshells-and-c2-frameworks/')" style="display: inline-flex; align-items: center; justify-content: center; gap: 8px; margin-right: 10px; margin-bottom: 10px; padding: 8px 16px; color: #ffffff; text-decoration: none; border-radius: 4px; font-size: 14px; font-weight: 500; transition: background-color 0.2s; background-color: #475569; border: none; cursor: pointer; font-family: inherit;"> Copy Link Related posts: CISA Adds SAP NetWeaver Zero-Day CVE-2025-31324 to KEV Database CrushFTP Hit by SSRF and Directory Traversal Vulnerabilities (CVE-2025-32102 & CVE-2025-32103) SAP Security Alert: May 2025 Patch Day Exposes Critical Threats! Splunk Issues Patches for Two Security Flaws: Windows Permission Misconfiguration and Reflected XSS Critical Vulnerability (CVE-2025-31498) Patched in c-ares DNS Library Written by@DdoS Β· Security ResearcherDo SonDo Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks. Tags: Brute Ratel CVE-2025-31324 cyberattack Heaven's Gate SAP NetWeaver security webshell Zero-Day Vulnerability Leave a Reply Cancel replyYou must be logged in to post a comment.