Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitywidely-deployed-product-advisoryend-of-life-softwareinternet-facing-service-vulnerability

Multiple Critical Vulnerabilities in Popular Enterprise Software and Devices

Updated 3mo agoFirst seen Nov 20, 20254 sources

Several critical vulnerabilities have been disclosed in widely used enterprise products, each posing significant security risks. A flaw in ASUSTOR devices (CVE-2025-13051) allows local attackers to escalate privileges to SYSTEM via DLL hijacking, potentially granting full control over affected systems. Separately, Apache Causeway is impacted by a remote code execution vulnerability (CVE-2025-64408) that enables authenticated attackers to execute arbitrary code through Java deserialization, threatening the integrity of applications built on this framework.

Additionally, the D-Link DIR-878 router, now at end-of-life, contains three unpatched remote code execution flaws that allow unauthenticated attackers to run commands remotely, leaving users exposed with no forthcoming security updates. Apache Tomcat is also affected by a critical path traversal vulnerability (CVE-2025-55752), which can be exploited under certain rewrite configurations to access sensitive directories, especially when HTTP PUT is enabled. Organizations using these products should urgently assess their exposure and apply mitigations or seek alternatives where patches are unavailable.

Share:
Multiple Critical Vulnerabilities in Popular Enterprise Software and Devices
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Nov 20, 20257mo ago

Apache Causeway RCE flaw CVE-2025-64408 disclosed

A critical vulnerability in Apache Causeway, tracked as CVE-2025-64408, was reported as enabling authenticated remote code execution through Java deserialization. The reference presents this as a newly reported vulnerability disclosure.

ASUSTOR privilege-escalation flaw CVE-2025-13051 disclosed

A critical vulnerability report described CVE-2025-13051 in ASUSTOR products, allowing local DLL hijacking that could lead to SYSTEM-level privilege escalation. The reference does not provide a separate patch or vendor response date.

Nov 19, 20257mo ago

D-Link DIR-878 reaches end of life with 3 unpatched RCE flaws reported

A report disclosed that the D-Link DIR-878 had reached end of life while three unauthenticated remote code execution vulnerabilities remained unpatched. The issue highlights continued exposure for users of the unsupported device.

Nov 18, 20257mo ago

Apache Tomcat path traversal flaw CVE-2025-55752 disclosed

A vulnerability report was published describing CVE-2025-55752, a path traversal vulnerability affecting Apache Tomcat. No additional remediation or exploitation details are provided in the reference.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Organizations
2 linked
Apache Software FoundationD-Link
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.