Check Point: Active Exploitation of Critical HPE OneView Vulnerability

Share a note:





Check Point’s investigation revealed an active and coordinated exploitation campaign targeting CVE-2025-37164, a critical remote code execution vulnerability affecting HPE OneView. The activity observed directly in Check Point telemetry is associated with the RondoDox botnet and represents a dramatic escalation from early probing attempts to large-scale automated attacks.

Check Point has already blocked tens of thousands of exploit attempts, underscoring both the severity of the vulnerability and the urgency for organizations to act.

On January 7, 2026, Check Point Research reported the campaign to CISA, and the vulnerability was added to KEV’s catalog of known exploitable vulnerabilities on the same day.

Vulnerability summary

On December 16, 2025, Hewlett Packard Enterprise HPE published an advisory for CVE-2025-37164, a critical remote code execution vulnerability in HPE OneView, which was reported by security researcher Nguyen Quoc Khanh. HPE OneView is an IT infrastructure management platform that automates the management of compute, storage and network resources and is widely used by organizations in a variety of industries.

The vulnerability resides in the exposed executeCommand REST API endpoint related to the identity pools functionality. The endpoint accepts information provided by an attacker without any authentication or authorization checks and executes it directly through the operating system runtime without any authentication or authorization checks.

This gives attackers a direct path to remote code execution on affected systems.

Early activity and exercise of protection

Check Point quickly addressed the vulnerability by implementing an emergency quantum intrusion prevention system on December 21. The first attempts at exploitation were discovered the same night. Preliminary analysis of our telemetry shows that the activity consisted mainly of direct attempts to use the proof of concept.

Active large-scale exploitation is observed

On January 7, 2026, Check Point Research noted a sharp escalation.

Between 05:45 and 09:20 UTC, we recorded more than 40,000 attack attempts using CVE-2025-37164. Analysis shows that these attempts were an automated botnet-driven exploit.

We link this activity to the RondoDox botnet based on the user agent’s distinctive string and observed commands, including those designed to download RondoDox malware from remote hosts.

An attempt at active exploitation.
An attempt at active exploitation.

The origin and objectives of the attack

Most of the activity we observed came from a single Dutch IP address that was widely reported as suspicious online. Check Point telemetry confirms that this threat actor is very active.

The campaign affected organizations in a variety of sectors, with the highest concentration of activity seen against government organizations, followed by the financial services and manufacturing sectors.

The targets were distributed all over the world. The United States suffered the most attacks, followed by Australia, France, Germany and Austria.

RondoDox botnet activity

RondoDox is a new Linux-based botnet that attacks Internet-connected IoT devices and web servers, mainly conducting distributed DDoS attacks and cryptocurrency mining.

First publicly disclosed in mid-2025, Check Point observed that RondoDox was actively exploiting known vulnerabilities, including December’s React2Shell vulnerability CVE-2025-55182, with a focus on unpatched edge and perimeter infrastructure.

Exploitation of CVE-2025-37164 follows this pattern directly.

What should organizations do?

The rapid transition from disclosure to mass exploitation leaves no room for maneuver.

Organizations using HPE OneView should apply patches immediately and ensure remedial controls are in place. The inclusion of CVE-2025-37164 in the KEV CISA catalog increases the urgency. This vulnerability is actively used and represents a real danger.

Check Point customers remain protected

Check Point’s Intrusion Prevention Systems (IPS) actively block attempts to exploit CVE-2025-37164 and similar vulnerabilities, protecting customers during the critical period between disclosure and remediation.

Check Point’s next-generation IPS firewall protection updates automatically. Whether a vulnerability was discovered years or minutes ago, Check Point customers remain protected from attempts to exploit vulnerable systems in their environment.

More details

Visits: 13

Share a note:





Leave a Reply

Your email address will not be published. Required fields are marked *