CVE-2018-25117: VestaCP Debian Installer Malicious Backdoor Supply Chain Compromise

Published Oct 15, 2025
·
Updated

VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a multi-stage DDoS bot that uses Lua for second- and third-stage components. The compromise leaked administrative credentials (base64-encoded admin password and server domain) to an external URL during installation and/or resulted in the installer dropping and executing a DDoS malware payload under local system privileges. Compromised servers were subsequently observed participating in large-scale DDoS activity. Vesta acknowledged exploitation in the wild in October 2018.

Affected Software

1 affected component
VestaCP VestaCP>=a3f0fa1<=ee03eff

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Do not use VestaCP Debian installers built from VestaCP commits a3f0fa1 (2018-05-31) through ee03eff (2018-06-13). Verify the git commit of any installer before deployment and obtain installers only from a verified, clean source or rebuild the installer from VestaCP source that is confirmed not to include these commits.

  2. Compensating control

    Prevent further DDoS participation by blocking or rate-limiting outbound traffic from affected hosts (apply firewall/ACL rules or egress filtering) and otherwise restrict network egress from systems that may have been installed with the compromised installer until they are verified clean or rebuilt.

  3. Operational

    Identify systems installed using the compromised installer (new installations since at least May 2018). For any system suspected or confirmed compromised (evidence of Linux/ChachaDDoS, dropped payloads, or participation in DDoS), immediately isolate the host from the network, reimage or fully reinstall the OS and applications, and rotate all administrative credentials (change VestaCP admin passwords and any other potentially exposed credentials). Invalidate existing sessions and keys.

  4. Operational

    Audit installation and network logs for signs of credential exfiltration during installation: search for occurrences of base64-encoded admin passwords and server domain being sent to external endpoints and investigate any connections to unknown external URLs made during installation. Record indicators of compromise for remediation and threat hunting.

Event History

Oct 15, 2025
CVE Published
via MITRE·01:23 AM
Data Sourced
via MITRE·01:23 AM
DescriptionWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-25117?

CVE-2018-25117 is considered a high severity vulnerability due to its potential for a supply-chain compromise and distribution of malicious software.

2

How do I fix CVE-2018-25117?

To fix CVE-2018-25117, ensure that you upgrade to a version of VestaCP beyond commit ee03eff.

3

What does CVE-2018-25117 affect?

CVE-2018-25117 affects VestaCP installations created from the compromised installer between May 31, 2018, and June 13, 2018.

4

What type of malware is associated with CVE-2018-25117?

CVE-2018-25117 is associated with the Linux/ChachaDDoS malware, which can be installed through the compromised VestaCP installer.

5

How can I tell if my VestaCP installation is compromised by CVE-2018-25117?

You can check if your VestaCP installation falls within the affected commits and is running an outdated version to determine if it is compromised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203