CVE-2019-25714Active Exploitation

LOWCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS command execution with web server privileges. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-03-26 (UTC).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-21: 3Mentions · 2026-04-22: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-04-22: 1Technical Details · 2026-04-21: 3Technical Details · 2026-04-22: 104-2104-22
Signal classification2 categories
Active Exploitation
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-213
Active Exploitation1Disclosure2
2026-04-221
Active Exploitation1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2019-25714 Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary … https://www.cve.org/CVERecord?id=CVE-2019-25714

    Post summary

    The text announces CVE-2019-25714, revealing an unauthenticated arbitrary file write flaw in Seeyon OA A8 that allows remote attackers to write files via the /seeyon/htmlofficeservlet endpoint.

    00010150
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Active Exploitation

    🚨 CVE-2019-25714: Seey... Unauthenticated file write to webroot + JSP execution = instant RCE on thousands of Chinese enterprise OA systems still running A8. #webshell #rce. https://zerodaysignal.com/vulnerability/CVE-2019-25714 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post highlights that CVE‑2019‑25714 is actively exploited, enabling immediate remote code execution via unauthenticated file write and JSP execution on thousands of Chinese enterprise OA systems.

    0001065
    218 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2019-25714 Exploit in the wild confirmed for CVE-2019-25714 (CVSS 9.3). Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyo... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2019-25714 has been confirmed in the wild with a CVSS of 9.3, involving an unauthenticated arbitrary file write vulnerability; no PoC, exploit code, or patch is discussed.

    00000101
    5.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2019-25714 Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary … https://www.cve.org/CVERecord?id=CVE-2019-25714 ----- Traducción: CVE-2019-25714 See… http://infoflow.cloud`

    Post summary

    The post announces CVE-2019-25714, detailing an unauthenticated file-write vulnerability in Seeyon OA A8 and linking to the CVE record, but provides no exploitation or patch information.

    0000016
    72 followersView on X

Explore more