ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA and FBI Raise Alerts on Exploited Flaws and Expanding HiatusRAT Campaign

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-7921
Improper Authentication Bypass in Multiple Hikvision Products

CVE-2017-7921 is an improper authentication flaw (CWE-287) in multiple Hikvision products that allows an attacker to defeat the devices' authentication checks. It is triggered by sending specially crafted requests to an affected device, causing it to treat the attacker as an authenticated user. A successful attacker gains privilege escalation on the device and access to sensitive information. Any organization running affected Hikvision products, particularly devices reachable from the internet, is affected; the source data does not specify the individual models or firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, confirming exploitation in the wild (ransomware use unknown), and EPSS assigns a ~100% probability of exploitation within 30 days.

Do: Upgrade affected Hikvision devices to vendor-fixed firmware per Hikvision's security advisories (the data here does not name specific fixed versions), and follow CISA's required actions or BOD 22-01 guidance if applicable. Reduce exposure by removing affected devices from direct internet access and restricting the management interface to trusted networks. Check device logs and configurations for signs of unauthenticated or unauthorized access.

9.8100% KEV
  • Hikvision
mass~1,000,000+ deployed devices, with hundreds of thousands internet-exposed
CVE-2018-9995
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-brand

TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

NVD description · AI analysis pending
9.883% PoC ×4
  • tbkvision tbk-dvr4216 firmware
  • tbkvision tbk-dvr4104 firmware
CVE-2020-25078
Unauthenticated Admin Password Disclosure in D-Link DCS-2530L/2670L Cameras

CVE-2020-25078 is an information-disclosure flaw in the unauthenticated /config/getuser endpoint of D-Link DCS-2530L and DCS-2670L network cameras, which allows a remote, unauthenticated attacker to retrieve the device's administrator password. It is triggered simply by sending a crafted request to that HTTP endpoint over the network, with no login or user interaction required. An attacker who obtains the administrator password can log into the camera's web interface to view footage, change settings, or pivot further into the network. Owners of a DCS-2530L running firmware before 1.06.01 Hotfix or a DCS-2670L running firmware through 2.02 with the camera's web interface reachable are affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-05 amid active-exploitation evidence (with FBI/CISA alerts on HiatusRAT campaigns targeting webcams and DVRs), and its EPSS score of 97.9% indicates a very high near-term exploitation probability.

Do: Upgrade DCS-2530L cameras to firmware 1.06.01 Hotfix or later, and for DCS-2670L apply the latest vendor hotfix release newer than 2.02 (check D-Link's support page, as the exact fixed version is not specified in this data). Do not expose the camera web interface directly to the internet (remove port forwards/UPnP mappings or restrict access via firewall), and check device logs or perimeter traffic for unauthenticated requests to /config/getuser. Because these devices are end-of-life, plan replacement if current mitigations or firmware updates are unavailable, consistent with BOD 22-01 guidance.

7.598% KEV
  • D-Link DCS-2530L camera firmware before 1.06.01 Hotfix
  • D-Link DCS-2670L camera firmware through 2.02 (fixed version not specified in source data)
  • D-Link DCS-4603 firmware
  • +6 more
moderatelikely on the order of tens of thousands of internet-exposed camera units (estimate; no authoritative counts in source data)
CVE-2020-8515
Unauthenticated Command Injection RCE in DrayTek Vigor3900/2960/300B Routers

CVE-2020-8515 is an unauthenticated OS command injection flaw (CWE-78) in the web management page of DrayTek Vigor3900, Vigor2960, and Vigor300B routers. An attacker can trigger it by sending crafted, unauthenticated HTTP requests to the router's management web interface, injecting shell metacharacters into commands executed by the device. Successful exploitation yields remote code execution on the router, allowing an attacker to install web shells, alter firewall/VPN settings, intercept traffic, or pivot into the protected network. Any organization running affected Vigor3900/2960/300B firmware with the management interface reachable from the internet is exposed; these models are commonly deployed as small-business and branch-office VPN gateways. The flaw is being actively exploited: CISA added it to the KEV on 2021-11-03 and EPSS assigns a 100% probability of exploitation within 30 days, though no public PoC is catalogued.

Do: Upgrade Vigor3900, Vigor2960, and Vigor300B to firmware 1.5.1.1 or later per DrayTek's instructions, as required by the CISA KEV entry. Do not expose the web management page directly to the internet, and inspect internet-facing units for indicators of compromise such as unexpected web shell files (e.g., webs.php), unknown administrator accounts, or altered firewall/VPN settings. If compromise is confirmed, perform a factory reset and reflash clean firmware, then restore configurations from trusted backups.

9.8100% KEV PoC
  • DrayTek Vigor3900 firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory); CISA lists 'Multiple Vigor Routers'
  • DrayTek Vigor2960 firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory)
  • DrayTek Vigor300B firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory)
large≈10,000–100,000 internet-exposed Vigor routers (total Vigor installed base in the millions)
CVE-2021-33044
Authentication Bypass in Dahua IP Camera Firmware

Dahua IP cameras and related products contain an authentication bypass flaw (CWE-287, Improper Authentication) that is triggered when the client supplies the NetKeyboard type argument during the authentication process, allowing the device to treat the session as authenticated without valid credentials. An unauthenticated remote attacker who can reach the camera's network interface can exploit this to gain unauthorized access to the device's management functions. Successful exploitation can expose camera video streams and device configuration and can serve as a foothold into the surrounding surveillance or corporate network. Any organization running affected Dahua IP camera firmware, particularly cameras exposed to the internet, is potentially affected. The flaw is confirmed to be exploited in the wild: it was added to the CISA KEV on 2024-08-21, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile), although no public PoC is known.

Do: Apply the mitigations or patched firmware specified in Dahua's security advisory for CVE-2021-33044; if mitigations are unavailable, discontinue use of the product as CISA's required action directs. Inventory internet-facing Dahua cameras and related devices, restrict their login interfaces from direct internet exposure, and review authentication logs for signs of prior exploitation. Ransomware use is listed as unknown, so treat any compromised camera as a potential network foothold and rotate any credentials used on the device.

9.8100% KEV PoC ×2
  • Dahua IP Camera Firmware
massplausibly millions of installed Dahua cameras worldwide, with likely >100,000 internet-exposed Dahua devices
CVE-2021-36260
Unauthenticated Command Injection in Hikvision Device Web Server

CVE-2021-36260 is a command injection flaw (CWE-78) in the web server embedded in a wide range of Hikvision security camera and related devices, caused by insufficient input validation. An attacker triggers it by sending a crafted HTTP request to the device's web management interface, allowing commands to be executed on the device without authentication. Successful exploitation grants unauthenticated remote code execution on the camera or recorder, letting an attacker take control of the device, pivot into the surrounding network, or use the devices as a botnet platform. Any Hikvision device running the affected web server firmware is at risk, which includes cameras, recorders, and other surveillance hardware deployed in homes, businesses, and government facilities. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 and carries a 99.9% EPSS probability of exploitation within 30 days, while no public proof-of-concept code is cataloged in the provided data and no CVSS score has been issued yet.

Do: Apply firmware updates issued by Hikvision per the vendor's instructions, as required by CISA's KEV listing for this vulnerability. Restrict the device web management interface to trusted networks or VPN access and avoid direct internet exposure. Review web server logs for anomalous HTTP requests to the device interface and signs of command execution, and prioritize internet-facing devices for patching first.

9.8100% KEV PoC ×3
  • Hikvision Embedded web server of Hikvision security cameras and related surveillance devices
massmillions of installed devices, with roughly hundreds of thousands to over a million Hikvision web interfaces exposed to the internet
CVE-2024-20767
Improper Access Control in Adobe ColdFusion Enables Arbitrary File Read

Adobe ColdFusion contains an improper access control flaw (CWE-284) that allows an unauthenticated attacker to read arbitrary files on the server's file system; per Adobe's advisory, an attacker could also access or modify restricted files. Exploitation occurs over the network with no authentication and no user interaction, but it requires the ColdFusion Administrator panel to be exposed to the internet. A successful attacker can retrieve restricted files, potentially exposing sensitive configuration and credential material stored on the server. Organizations running ColdFusion 2023.6 or earlier on the 2023 release, or 2021.12 or earlier on the 2021 release, with the admin panel reachable from the internet are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, thousands of exploit attempts were observed during the Christmas holiday, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade ColdFusion 2023 to a version later than 2023.6 and ColdFusion 2021 to a version later than 2021.12 per Adobe's advisory and CISA's required action. If patching must be deferred, keep the ColdFusion Administrator panel off the public internet by restricting it via firewall, VPN, or IP allowlisting, since internet exposure of the admin panel is required for exploitation. Given the KEV listing (2024-12-16) and thousands of observed exploit attempts over the Christmas holiday, organizations with internet-exposed ColdFusion servers should review logs for exploitation activity and treat prior exposure as a potential compromise.

7.499% KEV
  • Adobe ColdFusion 2023 2023.6 and earlier
  • Adobe ColdFusion 2021 2021.12 and earlier
largeon the order of 10,000-100,000 potentially exposed systems (tens of thousands of internet-reachable ColdFusion servers, of which only those with the…
CVE-2024-35250
Local Privilege Escalation in Microsoft Windows Kernel-Mode Driver

CVE-2024-35250 is an untrusted pointer dereference flaw (CWE-822) in a Microsoft Windows kernel-mode driver, where a pointer supplied by untrusted code is mishandled. A local attacker who can already execute code on a vulnerable Windows system can trigger the flaw to run code in kernel context. Successful exploitation yields elevation of privilege, typically to SYSTEM-level rights, which can be chained with other weaknesses for fuller system compromise. Practically all Windows installations are potentially affected, though the bug is not remotely exploitable and requires an attacker to first gain local access. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, EPSS assigns a 25% probability of exploitation within 30 days (98th percentile), and no public PoC is known.

Do: Apply Microsoft's security updates immediately — the flaw was fixed in Microsoft's June 2024 Patch Tuesday release, so confirm affected hosts are at or beyond that patch level using Microsoft's advisory and your patch telemetry. Because exploitation requires a local foothold, prioritize multi-user servers, shared workstations, and RDS/VDI hosts, and treat this bug as an escalation vector when hunting post-compromise activity. CISA KEV requires applying vendor mitigations (or discontinuing use) by the stated deadline; ransomware use is currently unknown.

7.825% KEV
  • Microsoft Windows
mass≈1 billion+ Windows devices (Windows exceeds one billion active devices worldwide)
CVE-2024-41592
DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand cha

DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.

NVD description · AI analysis pending
8.01% PoC
  • draytek vigor2952 firmware
  • draytek vigor2620 firmware
  • draytek vigor2915 firmware
  • +1 more
Full article646 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 17, 2024Network Security / IoT Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

The list of flaws is below -

  • CVE-2024-20767 (CVSS score: 7.4) - Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel (Patched by Adobe in March 2024)
  • CVE-2024-35250 (CVSS score: 7.8) - Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges (Patched by Microsoft in June 2024)

Taiwanese cybersecurity company DEVCORE, which discovered and reported CVE-2024-35250, shared additional technical details in August 2024, stating it's rooted in the Microsoft Kernel Streaming Service (MSKSSRV).

There are currently no details on how the shortcomings are being weaponized in real-world attacks, although proof-of-concept (PoC) exploits for both of them exist in the public domain.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary remediation by January 6, 2025, to secure their networks.

FBI Warns of HiatusRAT Targeting Web Cameras and DVRs

The development follows an alert from the Federal Bureau of Investigation (FBI) about HiatusRAT campaigns expanding beyond network edge devices like routers to scan Internet of Things (IoT) devices from Hikvision, D-Link, and Dahua located in the U.S., Australia, Canada, New Zealand, and the United Kingdom.

"The actors scanned web cameras and DVRs for vulnerabilities including CVE-2017-7921, CVE-2018-9995, CVE-2020-25078, CVE-2021-33044, CVE-2021-36260, and weak vendor-supplied passwords," the FBI said. "Many of these vulnerabilities have not yet been mitigated by the vendors."

The malicious activity, observed in March 2024, involved the use of open-source utilities called Ingram and Medusa for scanning and brute-force authentication cracking.

DrayTek Routers Exploited in Ransomware Campaign

The warnings also come as Forescout Vedere Labs, with intelligence shared by PRODAFT, revealed last week that threat actors have exploited security flaws in DrayTek routers to target over 20,000 DrayTek Vigor devices as part of a coordinated ransomware campaign between August and September 2023.

"The operation exploited a suspected zero-day vulnerability, enabling attackers to infiltrate networks, steal credentials, and deploy ransomware," the company said, adding the campaign "involved three distinct threat actors – Monstrous Mantis (Ragnar Locker), Ruthless Mantis (PTI-288) and LARVA-15 (Wazawaka) – who followed a structured and efficient workflow."

Monstrous Mantis is believed to have identified and exploited the vulnerability and systematically harvested credentials, which were then cracked and shared with trusted partners like Ruthless Mantis and LARVA-15.

The attacks ultimately allowed the collaborators to conduct post-exploitation activities, including lateral movement and privilege escalation, ultimately leading to the deployment of different ransomware families such as RagnarLocker, Nokoyawa, RansomHouse, and Qilin.

"Monstrous Mantis withheld the exploit itself, retaining exclusive control over the initial access phase," the company said. "This calculated structure allowed them to profit indirectly, as ransomware operators who successfully monetized their intrusions were obliged to share a percentage of their proceeds."

Ruthless Mantis is estimated to have successfully compromised at least 337 organizations, mainly located in the U.K. and the Netherlands, with LARVA-15 acting as an initial access broker (IAB) by selling the access it gained from Monstrous Mantis to other threat actors.

It's suspected that the attacks made use of a then zero-day exploit in DrayTek devices, as evidenced by the discovery of 22 new vulnerabilities that share root causes similar to CVE-2020-8515 and CVE-2024-41592.

"The recurrence of such vulnerabilities within the same codebase suggests a lack of thorough root cause analysis, variant hunting and systematic code reviews by the vendor following each vulnerability disclosure," Forescout noted.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/12/cisa-and-fbi-raise-alerts-on-exploited.html