In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
https://thehackernews.com/2025/07/over-600-laravel-apps-exposed-to-remote.html
https://www.infosecurity-magazine.com/news/androxgh0st-botnet-adopts-mozi/
https://hackread.com/androxgh0st-botnet-integrate-mozi-iot-vulnerabilities/
https://isc.sans.edu/diary/rss/31086
https://blogs.juniper.net/en-us/security/shielding-networks-against-androxgh0st
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-016a
https://github.com/Loaxert/CVE-2018-15133-PoC
https://github.com/4l3xBB/Exploits
https://github.com/Cr4zyD14m0nd137/Lab-for-cve-2018-15133
https://github.com/advisories/GHSA-qvqm-h22r-4cp9
https://github.com/NatteeSetobol/CVE-2018-15133-Lavel-Expliot
https://github.com/pwnedshell/Larascript
https://github.com/PwnedShell/Larascript
https://github.com/iansangaji/laravel-rce-cve-2018-15133
https://github.com/bukitbarisan/laravel-rce-cve-2018-15133
https://github.com/Prabesh01/Laravel-PHP-Unit-RCE-Auto-shell-uploader
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-15133