TGViewer
MahadSec MahadSec @mahadsec · 179 subscribers
Post #19 1.46K
🐞 CVE-2025-24813 — Apache Tomcat (CVSS 9.8)

A path equivalence bug in Tomcat’s Default Servlet.

If writes are enabled and partial PUT is allowed, an attacker can abuse filenames like file.Name to plant content where they shouldn’t and in the right setup, that leads to remote code execution.

RCE needs a few things lined up:
• Default Servlet writable (readonly=false)
• Partial PUT enabled
• File-based session persistence
• A deserialization gadget on the classpath

Default installs are usually fine. Misconfigured ones are not.

Fix: upgrade to Tomcat 11.0.3 / 10.1.35 / 9.0.99, keep the Default Servlet read-only, and avoid file-based session stores unless you need them.


❓ Want to practice it hands-on?

Solve Bucket on MahadSec:
🛡 https://my.mahadsec.com/standalone-labs/machine/bucket
  • 🔥 1
More from @mahadsec
  1. Sep 22, 2026🛡 New CTF challenges released 🏁 Capture The Flags Now: https://my.mahadsec.com/ctf/chall…
  2. Sep 21, 2026Post #23
  3. Sep 19, 2026🛡 SmarterMail: Unauthenticated file upload (CVE-2025-52691) Practice with Ring: 🔗 https:…
  4. Sep 17, 2026🇺🇿 O'zbekistondagi startuplar uchun taklif. 👨‍💻Hamma loyihasini qurish, investor topis…
  5. Sep 16, 2026🏁 Mahadsec CTF is also live now! Is solving machines too challenging right now? Start wit…
  6. Sep 11, 2026CVE-2025-55182 — React2Shell 🔴 CVSS 10.0. Unauthenticated RCE in React Server Components.…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →