CVE detail
CVE-2025-0994
Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
A now-patched high-severity security flaw affecting Trimble Cityworks — a specialized software used by local governments in the US, utilities, and public agencies to manage their infrastructure and community services—was abused by Chinese hackers to compromise systems before a patch was available. According to a Talos intelligence report, the flaw (tracked as CVE-2025-0994) in the […]
newswww.csoonline.comMay 23, 2025, 11:40 AMA Chinese threat actor exploited a zero-day vulnerability in Trimble Cityworks to hack local government entities in the US.
newswww.securityweek.comMay 23, 2025, 9:30 AM- Chinese threat actors exploited Trimble Cityworks flaw to breach U.S. local government networksSecurity Affairs
A Chinese threat actor, tracked as UAT-6382, exploited a patched Trimble Cityworks flaw to deploy Cobalt Strike and VShell. Cisco Talos researchers attribute the exploitation of the CVE-2025-0994 in Trimble Cityworks to Chinese-speaking threat actor UAT-6382, based on tools and TTPs used in the intrusions. The vulnerability CVE-2025-0994 (CVSS v4 score of 8.6) is a […]
newssecurityaffairs.comMay 23, 2025, 6:27 AM - 10th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 10th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Grubhub, the US-based online food ordering and delivery platform, suffered a data breach due to unauthorized access through a compromised third-party service provider’s account. The incident exposed personal details of customers, drivers, […]
vendorresearch.checkpoint.comFeb 10, 2025, 1:53 PM Hackers are exploiting a high-severity remote code execution (RCE) flaw in Cityworks deployments — a GIS-centric asset and work order management software — to execute codes on a customers’ Microsoft web servers. In a coordinated advisory with the US Cybersecurity and Infrastructure Security Agency (CISA), Cityworks’ developer Trimble said that the vulnerability, tracked as CVE-2025-0994 […]
newswww.csoonline.comFeb 10, 2025, 12:57 PM- U.S. CISA adds Trimble Cityworks flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Trimble Cityworks vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Trimble Cityworks vulnerability, tracked as CVE-2025-0994, to its Known Exploited Vulnerabilities (KEV) catalog. Trimble Cityworks is a GIS-centric asset management and permitting software designed for local governments, utilities, and […]
newssecurityaffairs.comFeb 7, 2025, 9:54 PM Trimble Cityworks is affected by a zero-day vulnerability that has been exploited in attacks involving the delivery of malware.
newswww.securityweek.comFeb 7, 2025, 9:55 AMNo excerpt available.
Mitigationwww.cisa.govFeb 6, 2025, 4:15 PMNo excerpt available.
Mitigationwww.cisa.govFeb 6, 2025, 4:15 PM- https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-05-docx/0?learn.assetlifecycle.trimble.com
No excerpt available.
Vendor Advisorylearn.assetlifecycle.trimble.comFeb 6, 2025, 4:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-65617CVSS 8.8 · High
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository…
- CVE-2026-63077CVSS 9.8 · Critical
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
- CVE-2026-15962CVSS 8.8 · High
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. Thi…
- CVE-2026-50517CVSS 9.9 · Critical
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
- CVE-2026-21655CVSS 8.7 · High
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
- CVE-2026-65497CVSS 7.2 · High
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.