ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-6862
Buffer Overflow in Multiple NETGEAR Devices Allows Auth Bypass and RCE

A buffer overflow (CWE-119) affects multiple NETGEAR networking devices and can be exploited remotely, allowing an attacker to bypass authentication on the device and potentially execute arbitrary code. The flaw is triggered when the affected device processes crafted network input, overflowing a memory buffer such that authentication checks can be bypassed or attacker-controlled code runs on the device. A successful attacker gains unauthorized access to the device's administrative functions or code execution on the device itself, providing a foothold for traffic interception, botnet enrollment, or pivoting into the network behind it. Any home or small-office operator running an affected NETGEAR model on unpatched firmware is affected; the specific model and firmware ranges are enumerated in NETGEAR's advisory rather than in this data. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08, EPSS puts its 30-day exploitation probability at 42.7% (99th percentile), while no public PoC is cataloged and ransomware use is unknown.

Do: Update affected NETGEAR devices to the fixed firmware listed in NETGEAR's security advisory for your exact model (check the model on the device label and the NETGEAR support page), since firmware is released per model. Until patched, disable or restrict remote/WAN administration so the web management interface is not exposed to the internet, and restrict admin access to trusted hosts. Because the flaw is on CISA's KEV catalog, federal agencies must patch by the required deadline, and defenders should prioritize any internet-exposed units.

9.843% KEV
  • NETGEAR
mass≈1M+ deployed NETGEAR devices, plausibly >100,000 internet-exposed (public-scan counts; exact unpatched count unknown)
CVE-2018-0171
Unauthenticated RCE/DoS in Cisco IOS & IOS XE Smart Install

CVE-2018-0171 is a critical (CVSS 9.8) buffer-overflow vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE, caused by improper validation of packet data (CWE-20, CWE-787). An unauthenticated, remote attacker can trigger it by simply sending a crafted Smart Install message to TCP port 4786 on an affected device, with no credentials or user interaction required. A successful exploit can cause a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution, giving the attacker full control of the switch or router. Any IOS or IOS XE device running the Smart Install service is affected — a configuration commonly present on Catalyst switches — and devices exposed to the internet on TCP 4786 are at direct risk. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog, and both Russian (Static Tundra, FSB-linked) and Chinese (Salt Typhoon) state-sponsored actors have exploited it to compromise unpatched, often end-of-life, Cisco network devices at hundreds of organizations worldwide.

Do: Upgrade IOS/IOS XE to a fixed release per Cisco's advisory (Bug ID CSCvg76186); for end-of-life hardware that cannot be patched, plan replacement given active nation-state targeting of unpatched devices. If Smart Install is not in use, disable it with 'no vstack'; otherwise restrict TCP port 4786 with ACLs to trusted management hosts. Audit internet-facing switches and routers for Smart Install enabled and TCP 4786 exposed, and prioritize those devices for remediation.

9.899% KEV
  • Cisco IOS Devices running affected IOS releases with the Smart Install feature enabled (exact affected/fixed release ranges per Cisco advisory, Bug ID CSCvg76186; Smart I
  • Cisco IOS XE Devices running affected IOS XE releases with the Smart Install feature enabled (exact affected/fixed release ranges per Cisco advisory, Bug ID CSCvg76186)
mass≈250,000+ internet-exposed devices with TCP/4786 open, on top of a multi-million-device IOS/IOS XE installed base
CVE-2018-13382
Unauthenticated SSL VPN Account-Takeover Flaw in Fortinet FortiOS and FortiProxy

CVE-2018-13382 is an improper authorization flaw (CWE-863) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy that fails to properly authorize password-change requests. An unauthenticated attacker who can reach the SSL VPN web portal can send specially crafted HTTP requests to modify the password of an SSL VPN web-portal user without knowing the existing credentials. This effectively hands the attacker control of the victim's VPN account, enabling login through the portal and potential follow-on access to the internal network, consistent with the integrity-only CVSS 3.1 score of 7.5 (High). Any organization running affected versions - FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8 or 5.4.1-5.4.10, or FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6 or 1.0.0-1.0.7 - with the SSL VPN web portal enabled is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2022-01-10 with known ransomware use, EPSS estimates an 81.7% probability of exploitation within 30 days, and NSA/NCSC advisories warn that APT groups are exploiting VPN vulnerabilities of this kind.

Do: Apply updates to all affected FortiOS and FortiProxy deployments per Fortinet's instructions, as this is the CISA KEV required action, prioritizing internet-facing SSL VPN portals. Until patched, limit exposure of the SSL VPN web portal and audit authentication logs for unexpected password changes or unauthenticated requests to the portal. Given known ransomware and APT exploitation, force a password reset on VPN accounts whose credentials may have been tampered with.

7.582% KEV ransomware
  • Fortinet FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8, 5.4.1-5.4.10
  • Fortinet FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6, 1.0.0-1.0.7
masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL VPN endpoints (estimate)
CVE-2018-14847
Directory Traversal in MikroTik RouterOS Winbox Interface (Unauthenticated File Read)

CVE-2018-14847 is a directory traversal (CWE-22) vulnerability in the Winbox interface of MikroTik RouterOS through version 6.42. An unauthenticated remote attacker can send crafted Winbox requests that traverse directories to read arbitrary files on the device, while authenticated attackers can also write arbitrary files. By reading files an attacker can retrieve sensitive device data such as stored credentials or configuration, and file write capability can support further compromise of the router. Any MikroTik router or device running RouterOS at or below 6.42 with the Winbox interface reachable is affected, which includes large numbers of internet-exposed edge and ISP devices. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-12-01), has multiple public PoCs, and compromised MikroTik routers have been used by threats such as Trickbot (as C2 proxies) and the Mēris botnet, with public scans reporting over 300,000 vulnerable devices.

Do: Apply MikroTik's updates per vendor instructions, moving RouterOS above version 6.42, prioritizing devices with Winbox reachable from untrusted networks. Until patched, restrict or disable Winbox access from WAN/untrusted interfaces to limit unauthenticated file reads. Given known botnet abuse of this flaw, check devices for signs of compromise and rotate credentials that may have been exposed via file reads.

9.196% KEV PoC ×7
  • mikrotik routeros through 6.42 (all versions at or below 6.42)
mass≈300,000+ internet-exposed MikroTik devices
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
CVE-2019-15271
Authenticated Deserialization RCE in Cisco RV016/RV042/RV042G/RV082 Routers

CVE-2019-15271 is a deserialization of untrusted data flaw (CWE-502) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, and RV082 VPN routers, caused by insufficient input validation of the HTTP payload. An authenticated, remote attacker—someone with valid credentials or an active session token—triggers it by sending a crafted HTTP request to the device's management web interface. Successful exploitation lets the attacker execute arbitrary commands with root privileges, giving full control of the router (traffic manipulation, pivoting into the network, and persistence). Any organization running these Small Business VPN routers is affected, especially where the management interface is reachable from the WAN or internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2022-06-08, though no public PoC is known and ransomware linkage is unknown; EPSS estimates a ~6% (93rd percentile) chance of exploitation within 30 days.

Do: Apply updated firmware from Cisco per the vendor advisory — this is the required action in the CISA KEV entry — and, since these are older Small Business models with no guarantee of ongoing fixes, plan for hardware retirement. Until patched, do not expose the HTTP/HTTPS management interface to the internet (restrict it to trusted management hosts or VPN), use strong unique admin credentials, and review devices for unexpected sessions or configuration changes. Treat internet-exposed RV016/RV042/RV042G/RV082 units as potentially compromised given the KEV listing, and note recent reporting of network-equipment targeting by China-linked actors when prioritizing incident review.

8.86% KEV
  • Cisco RV016 Multi-WAN VPN Router firmware
  • Cisco RV042 Dual WAN VPN Router firmware
  • Cisco RV042G Dual Gigabit WAN VPN Router firmware
  • +1 more
largetens of thousands of internet-exposed devices (estimate)
CVE-2019-1652
Authenticated Command Injection in Cisco RV320/RV3325 Small Business Routers

CVE-2019-1652 is an improper input validation flaw (CWE-20, leading to command injection per CWE-78) in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN routers. An authenticated, remote attacker who already holds administrative privileges on the device exploits it by sending crafted HTTP POST requests to the management interface, and a successful exploit allows arbitrary command execution as root on the underlying Linux shell. Because administrative credentials are required, the bug is typically a second stage of an attack on an internet-facing edge router rather than a standalone entry point. All RV320 and RV325 routers running firmware predating the firmware updates Cisco released are affected, and these models have since reached end-of-life. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2022-03-03, carries a 95.9% EPSS probability (100th percentile), has had public PoCs since 2019, and news coverage reports attackers — including China-linked groups — targeting the roughly 9,000 RV320/RV325 units exposed online.

Do: Apply the firmware updates Cisco released for the RV320/RV325 per the vendor advisory, as required by the CISA KEV listing, and since these routers are end-of-life, plan hardware replacement where the updated firmware cannot be installed. In the interim, restrict access to the web-based management interface to trusted networks only and check exposed devices for signs of compromise, given active targeting by China-linked threat actors.

7.296% KEV PoC ×5
  • Cisco Small Business RV320 Dual Gigabit WAN VPN Router (firmware)
  • Cisco Small Business RV325 Dual Gigabit WAN VPN Router (firmware)
moderate≈9,000+ internet-exposed RV320/RV325 routers per public scans; total deployed base unknown but larger
CVE-2019-16920
Command Injection in Multiple D-Link Routers Enables Full Device Compromise

Multiple D-Link routers contain a command injection flaw (CWE-78) in which attacker-controlled input is executed as operating system commands by the device. An attacker who triggers the flaw can run arbitrary commands on the router with system privileges, achieving full compromise of the device, from which they can intercept or redirect traffic, pivot to the local network, or persist on the device. The specific affected models and firmware version ranges are not enumerated in the available data, but CISA notes the impacted product line is end-of-life, so only devices still in service are at risk. This vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing means defenders should treat exploitation as active, not theoretical.

Do: Inventory your environment for D-Link routers and identify any running the affected end-of-life models; per CISA's required action, disconnect or retire them if still in use since they no longer receive fixes. If a device must remain in service, restrict management access (disable WAN-side web administration, limit it to trusted management networks) and monitor for compromise indicators. Confirm whether any internet-facing D-Link routers are exposed and prioritize replacement of EOL units.

9.8100% KEV PoC ×2
  • D-Link
massplausibly hundreds of thousands of internet-exposed D-Link routers and millions sold overall; exact count of in-use affected units unknown
CVE-2019-19781
Unauthenticated path traversal RCE in Citrix ADC, Gateway, and SD-WAN WANOP

CVE-2019-19781 is a path-traversal flaw (classified CWE-22, though CISA's description calls it unspecified) in Citrix ADC (formerly NetScaler ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances that lets an unauthenticated remote attacker traverse directories via crafted requests and execute arbitrary commands on the appliance, typically with root privileges. It is triggered by sending specially crafted directory-traversal requests (crafted URLs/requests to the appliance's management or VPN endpoints), which lets the attacker write files and run commands with no credentials. Successful exploitation yields arbitrary code execution on the appliance, enabling theft of VPN/ADC credentials, lateral movement into the corporate network, and installation of persistent backdoors. Any organization running affected ADC, Gateway, or SD-WAN WANOP firmware is affected, with internet-facing gateways used for remote access at the highest risk. Exploitation is confirmed in the wild: the vulnerability is on CISA's KEV (added 2021-11-03) with known ransomware use, EPSS assigns near-certain (100.0%) probability of exploitation within 30 days, and no public PoC is listed despite confirmed abuse.

Do: Upgrade Citrix ADC, Gateway, and SD-WAN WANOP appliances to the fixed firmware builds listed in Citrix advisory CTX267020; if patching cannot be done immediately, apply Citrix's published interim mitigation and restrict internet exposure to the appliance. Because exploitation grants root code execution and persistence, after patching hunt for indicators of compromise (unexpected nsroot account, modified system files, crontab/scheduled entries), kill all active and inactive sessions, and rotate appliance and VPN credentials. Prioritize internet-facing gateways and comply with CISA's required action to apply vendor updates.

9.8100% KEV ransomware
  • Citrix Application Delivery Controller (ADC) Supported ADC firmware lines in effect at disclosure (10.5, 11.0, 11.1, 12.0, 12.1, 13.0) prior to patched builds, per Citrix advisory CTX267020; exact builds n
  • Citrix Gateway Supported Gateway firmware lines (sharing the ADC codebase, same affected releases 10.5-13.0) prior to patched builds, per Citrix advisory; exact builds not spe
  • Citrix SD-WAN WANOP Appliance Affected appliance models (4000, 4100, 5000, 5100) running pre-patch firmware in the 10.2.1-11.4.1 range, per Citrix advisory; exact builds not specified in the
massroughly 80,000-100,000+ internet-exposed Citrix ADC/Gateway appliances at the time of disclosure, with a far larger total installed base (including…
CVE-2019-7195
+2 in the same advisory: …7192 …7194
Path Traversal in QNAP Photo Station Enables Unauthenticated RCE

CVE-2019-7195 is a path traversal flaw (CWE-22, external control of file name or path) in QNAP's Photo Station multimedia application, in which an attacker-supplied file name or path is not properly validated. Per its CVSS vector (AV:N/AC:L/PR:N/UI:N), it is exploited over the network with no authentication and no user interaction, letting an unauthenticated remote attacker access or modify system files; a public proof of concept demonstrates chaining the flaw to full remote command execution against QTS with Photo Station 6.0.3. Successful exploitation gives an attacker the ability to read, alter, and execute code on the NAS, which has been leveraged for ransomware deployments. Any QNAP NAS device running Photo Station, particularly with the web interface reachable from the internet, is affected. Exploitation is confirmed in the wild: the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-08 with known ransomware use, and EPSS estimates an 89.7% probability of exploitation in the next 30 days.

Do: Update Photo Station to the latest version available for your QTS release, following QNAP's instructions (the action CISA requires for KEV entries); if patching is not immediately possible, restrict access to the Photo Station web interface to trusted networks or a VPN. Because ransomware use is known, also check exposed NAS for signs of compromise after patching, such as unexpected files, unknown user accounts, or unfamiliar scheduled tasks.

9.890% KEV ransomware PoC
  • QNAP Photo Station Prior Photo Station releases (public PoC tested against Photo Station 6.0.3 on QTS); QNAP recommends updating Photo Station to the latest versions
large≈tens of thousands (up to ~100,000) of internet-exposed QNAP Photo Station instances (public scans show hundreds of thousands of internet-visible QNAP NAS…
CVE-2019-7193
Unauthenticated Remote Code Execution in QNAP QTS via Improper Input Validation

CVE-2019-7193 is an improper input validation flaw (CWE-20) in QNAP's QTS NAS operating system, affecting its network-facing Photo Station web application, that allows remote, unauthenticated attackers to inject arbitrary code into the system. It is triggered by crafted requests sent to the Photo Station/QTS web interface, and the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that exploitation requires no credentials, privileges, or user interaction; a public proof-of-concept demonstrates remote command execution against QTS running Photo Station 6.0.3. A successful attacker gains the ability to execute arbitrary code on the NAS, which typically means full control of the device and its stored data, creating a stepping stone for data theft and ransomware deployment. Any organization or individual running QNAP QTS with the Photo Station component enabled is affected, especially devices whose web interface is exposed to the internet. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-06-08 with known ransomware use, and its EPSS score of 14.4% (96th percentile) indicates an elevated near-term probability of exploitation.

Do: Update QTS to the latest version available for your model per QNAP's instructions, as the vendor states updating to current QTS releases fixes the vulnerability; if patching is delayed, restrict or disable internet exposure of Photo Station and the QTS web UI. Review NAS devices for signs of compromise such as unknown processes, unexpected scheduled jobs, modified files, or ransomware artifacts, since known exploitation includes ransomware campaigns and internet-exposed QNAP NAS are frequent targets of both criminal and state-linked actors.

9.814% KEV ransomware PoC
  • QNAP QTS
massseveral hundred thousand internet-exposed QNAP NAS devices (installed base in the millions; share running Photo Station unknown)
CVE-2020-29583
Hard-Coded 'zyfwp' Admin Backdoor in Zyxel USG Firewall Firmware 4.60

Zyxel USG-series firewall/VPN gateway firmware version 4.60 ships with an undocumented built-in account named 'zyfwp' whose password is unchangeable and stored in cleartext in the firmware image, making the credentials effectively public once the firmware is examined (use of hard-coded credentials, CWE-522). An unauthenticated attacker who can reach the device's SSH server or web management interface can log in with these embedded credentials and gain full administrator privileges, enabling configuration changes, theft of credentials or logs, and pivoting into the networks the firewall protects; the flaw scores 9.8 (CVSS 3.1) because it is network-exploitable with no privileges or user interaction required. Affected products are the twelve Zyxel USG models listed by CISA (USG20-VPN through USG2200), widely deployed in small/medium-business, branch-office, and ISP/MSP-managed networks. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile), and a public PoC write-up plus news reports of active attacks against Zyxel firewalls and VPNs are available.

Do: Upgrade affected USG devices to a firmware release later than 4.60 per Zyxel's advisory (CISA's required action is to apply vendor updates). Until patched, restrict SSH and web management access to trusted networks and review device logs for logins by the 'zyfwp' account, since its password is public and cannot be changed on vulnerable firmware; check for signs of compromise when upgrading.

9.890% KEV PoC
  • Zyxel USG20-VPN firmware 4.60
  • Zyxel USG20W-VPN firmware 4.60
  • Zyxel USG40 firmware 4.60
  • +9 more
largetens of thousands of internet-exposed Zyxel USG firewalls (order 10^4-10^5 devices; total installed base likely higher)
CVE-2020-8515
Unauthenticated Command Injection RCE in DrayTek Vigor3900/2960/300B Routers

CVE-2020-8515 is an unauthenticated OS command injection flaw (CWE-78) in the web management page of DrayTek Vigor3900, Vigor2960, and Vigor300B routers. An attacker can trigger it by sending crafted, unauthenticated HTTP requests to the router's management web interface, injecting shell metacharacters into commands executed by the device. Successful exploitation yields remote code execution on the router, allowing an attacker to install web shells, alter firewall/VPN settings, intercept traffic, or pivot into the protected network. Any organization running affected Vigor3900/2960/300B firmware with the management interface reachable from the internet is exposed; these models are commonly deployed as small-business and branch-office VPN gateways. The flaw is being actively exploited: CISA added it to the KEV on 2021-11-03 and EPSS assigns a 100% probability of exploitation within 30 days, though no public PoC is catalogued.

Do: Upgrade Vigor3900, Vigor2960, and Vigor300B to firmware 1.5.1.1 or later per DrayTek's instructions, as required by the CISA KEV entry. Do not expose the web management page directly to the internet, and inspect internet-facing units for indicators of compromise such as unexpected web shell files (e.g., webs.php), unknown administrator accounts, or altered firewall/VPN settings. If compromise is confirmed, perform a factory reset and reflash clean firmware, then restore configurations from trusted backups.

9.8100% KEV PoC
  • DrayTek Vigor3900 firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory); CISA lists 'Multiple Vigor Routers'
  • DrayTek Vigor2960 firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory)
  • DrayTek Vigor300B firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory)
large≈10,000–100,000 internet-exposed Vigor routers (total Vigor installed base in the millions)
CVE-2021-22893
Use-After-Free RCE in Ivanti Pulse Connect Secure License Services

Ivanti Pulse Connect Secure, a widely deployed SSL VPN appliance, contains a use-after-free vulnerability in its license services. A remote, unauthenticated attacker can trigger the flaw via the license services and gain arbitrary code execution on the appliance, which is a high-value target because it terminates VPN sessions for enterprise networks. Any organization running an affected Pulse Connect Secure release is potentially affected; the source data does not specify exact version ranges, so administrators should compare their release against Ivanti's advisory. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and its 47.2% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days.

Do: Apply the updates per Ivanti's instructions immediately, as CISA's required action specifies. Because exploited appliances have often retained persistent webshells/backdoors even after patching, also hunt for indicators of compromise (modified appliance files, unexpected processes or accounts) and follow Ivanti's remediation guidance rather than only installing the update. Until patched, restrict or closely monitor internet access to the appliance.

10.047% KEV ransomware
  • Ivanti Pulse Connect Secure
largetens of thousands of internet-exposed Pulse Connect Secure VPN appliances (order of magnitude ~10^4-10^5)
Full article777 words · extracted from securityaffairs.com · click to collapse

China-linked threat actors have breached telecommunications companies and network service providers to spy on the traffic and steal data.

US NSA, CISA, and the FBI published a joint cybersecurity advisory to warn that China-linked threat actors have breached telecommunications companies and network service providers.

The nation-state actors exploit publicly known vulnerabilities to compromise the target infrastructure. 

The attackers also targeted Small Office/Home Office (SOHO) routers and Network Attached Storage (NAS) devices to use them as additional access points to route command and control (C2) traffic and midpoints to carry out attacks on other entities.

Below is top network device CVEs exploited by PRC nation-state actors since 2020:

Vendor                                       CVE                                  Vulnerability Type
CiscoCVE-2018-0171Remote Code Execution
CVE-2019-15271RCE
CVE-2019-1652RCE
CitrixCVE-2019-19781RCE
DrayTekCVE-2020-8515RCE
D-LinkCVE-2019-16920RCE
FortinetCVE-2018-13382Authentication Bypass
MikroTikCVE-2018-14847Authentication Bypass
NetgearCVE-2017-6862RCE
PulseCVE-2019-11510Authentication Bypass
CVE-2021-22893RCE
QNAPCVE-2019-7192Privilege Elevation
CVE-2019-7193Remote Inject
CVE-2019-7194XML Routing Detour Attack
CVE-2019-7195XML Routing Detour Attack
ZyxelCVE-2020-29583Authentication Bypass

Chinese hackers employed open-source tools for reconnaissance and vulnerability scanning, according to the government experts, they have utilized open-source router specific software frameworks, RouterSploit and RouterScan [T1595.002], to identify vulnerable devices to target.

The RouterSploit Framework allows operators to scan for vulnerable embedded devices, while RouterScan allows for the scanning of IP addresses for vulnerabilities. Both tools could be used to target SOHO and other routers manufactured by major industry providers, including Cisco, Fortinet, and MikroTik.

“Upon gaining an initial foothold into a telecommunications organization or network service provider, PRC state-sponsored cyber actors have identified critical users and infrastructure including systems critical to maintaining the security of authentication, authorization, and accounting. After identifying a critical Remote Authentication Dial-In User Service (RADIUS) server, the cyber actors gained credentials to access the underlying Structured Query Language (SQL) database [T1078] and utilized SQL commands to dump the credentials [T1555], which contained both cleartext and hashed passwords for user and administrative accounts.” reads the advisory published by the US agencies. “Having gained credentials from the RADIUS server, PRC state-sponsored cyber actors used those credentials with custom automated scripts to authenticate to a router via Secure Shell (SSH), execute router commands, and save the output [T1119].”

The agencies also provide a list of recommendations to mitigate and detect these attacks:

  • Keep systems and products updated and patched as soon as possible after patches are released [D3-SU] . Consider leveraging a centralized patch management system to automate and expedite the process.
  • Immediately remove or isolate suspected compromised devices from the network [D3-ITF] [D3-OTF].
  • Segment networks to limit or block lateral movement [D3-NI]. 
  • Disable unused or unnecessary network services, ports, protocols, and devices [D3-ACH] [D3-ITF] [D3-OTF]. 
  • Enforce multifactor authentication (MFA) for all users, without exception [D3-MFA]. 
  • Enforce MFA on all VPN connections [D3-MFA]. If MFA is unavailable, enforce password complexity requirements [D3-SPP]. 
  • Implement strict password requirements, enforcing password complexity, changing passwords at a defined frequency, and performing regular account reviews to ensure compliance [D3-SPP].
  • Perform regular data backup procedures and maintain up-to-date incident response and recovery procedures. 
  • Disable external management capabilities and set up an out-of-band management network [D3-NI].
  • Isolate Internet-facing services in a network Demilitarized Zone (DMZ) to reduce the exposure of the internal network [D3-NI].
  • Enable robust logging of Internet-facing services and monitor the logs for signs of compromise [D3-NTA] [D3-PM].
  • Ensure that you have dedicated management systems [D3-PH] and accounts for system administrators. Protect these accounts with strict network policies [D3-UAP].
  • Enable robust logging and review of network infrastructure accesses, configuration changes, and critical infrastructure services performing authentication, authorization, and accounting functions [D3-PM]. 
  • Upon responding to a confirmed incident within any portion of a network, response teams should scrutinize network infrastructure accesses, evaluate potential lateral movement to network infrastructure and implement corrective actions commensurate with their findings.

Security Affairs is one of the finalists for the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS. I ask you to vote for me again (even if you have already done it), because this vote is for the final.

Please vote for Security Affairs and Pierluigi Paganini in every category that includes them (e.g. sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog”)

To nominate, please visit: 

https://docs.google.com/forms/d/e/1FAIpQLSdNDzjvToMSq36YkIHQWwhma90SR0E9rLndflZ3Cu_gVI2Axw/viewform

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, China-linked threat actors)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/132042/apt/us-warns-china-linked-threat-actors.html