Security Affairs newsletter Round 520 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20035 | Authenticated OS Command Injection in SonicWall SMA100 Appliances CVE-2021-20035 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the management interface of SonicWall SMA100 series appliances. A remote attacker who has authenticated with low-level privileges can inject arbitrary operating system commands, which are executed on the appliance as the 'nobody' user. Per the CVSS scoring, the primary impact is on availability, potentially leading to denial of service, though command execution on the appliance could facilitate further abuse. The flaw affects SMA 200, 210, 400, 410, and 500v firmware. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-16, and related reporting describes ongoing attacks against SonicWall SMA 100 devices — including by threat group UNC6148 deploying the OVERSTEP rootkit and tailored backdoor malware, some against fully patched appliances — so defenders should treat this as actively exploited. Do: Patch to the fixed firmware release specified in the SonicWall advisory for your SMA model as soon as possible; federal agencies must follow the BOD 22-01 mitigation deadline per the CISA KEV required action. Restrict the management interface to trusted networks, enforce MFA on the portal, and hunt for signs of compromise such as the OVERSTEP rootkit, unexpected persistence, or unfamiliar accounts, since reporting indicates tailored backdoor malware in recent SMA 100 attacks. | 6.5 | 4% | KEV |
| large≈ tens of thousands of internet-exposed SMA 100-series appliances (order of magnitude 10k–100k) | |
| CVE-2025-24054 | NTLM Hash Disclosure Spoofing Vulnerability in Microsoft Windows CVE-2025-24054 is a spoofing vulnerability in Microsoft Windows NTLM caused by external control of a file name or path (CWE-73): when Windows processes a file whose name or path points to an attacker-controlled resource, the system is induced to authenticate via NTLM to that destination, disclosing the user's NTLM hash. An unauthorized network attacker triggers the flaw by convincing a user to interact with a crafted file, for example downloading or opening a malicious file, which sends NTLM credentials to a host of the attacker's choosing. With the captured NTLM hash, the attacker can attempt relay or offline cracking to spoof and impersonate the user on the network; no privileges are required, but user interaction is needed (CVSS 3.1: 5.4, medium). Any unpatched Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), or Windows Server 2008, 2012, 2016, or 2019 system in environments that use NTLM authentication is affected. The flaw is being actively exploited: CISA added it to the KEV catalog on 2025-04-17, EPSS puts the 30-day exploitation probability at about 59% (99th percentile), public proof-of-concept exploits exist, and multiple attack campaigns have been reported, including targeting of organizations in Poland and Romania shortly after the patch became available. Do: Apply Microsoft's April 2025 security updates across all listed Windows 10, Windows 11, and Windows Server releases and confirm updated builds through patch-management reporting; the flaw was added to CISA's KEV on 2025-04-17, so federal agencies must patch per BOD 22-01 deadlines or apply vendor mitigations. As interim mitigation, restrict outbound NTLM authentication (for example by blocking outbound TCP 445/139 to untrusted hosts, enforcing SMB signing, or removing NTLM where feasible) and hunt for anomalous outbound NTLM authentication following user file downloads or opening of untrusted shortcut files. | 5.4 | 59% | KEV PoC ×3 |
| masshundreds of millions of Windows devices (desktops and servers on the affected Windows 10, Windows 11, and Windows Server releases with NTLM in use) | |
| CVE-2025-30406 | Hard-coded machineKey enables unauthenticated deserialization RCE in Gladinet CentreStack and Triofox Gladinet CentreStack (and, per CISA, the companion product Triofox) ships with a hard-coded ASP.NET machineKey in the portal's web.config, which is used to protect ViewState and similar serialized data. An attacker who knows this fixed key can craft a serialized payload and submit it to the network-facing portal, where server-side deserialization executes it, yielding unauthenticated remote code execution (CVSS 9.8, no privileges or user interaction required). Successful RCE gives attackers full control of the file-sharing server (high confidentiality, integrity and availability impact); public reporting indicates attackers have abused the flaw to gain unauthorized access and install remote access tools. Anyone running the affected CentreStack builds is exposed, with self-hosted deployments at SMBs and MSP-hosted environments the typical footprint. The flaw was exploited in the wild in March 2025, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-04-08, and carries an EPSS of 94.3% (100th percentile). Do: Upgrade CentreStack to 16.4.10315.56368 or later, and apply the equivalent vendor fix for Triofox; as an interim mitigation, administrators can delete the hard-coded machineKey defined in portal\web.config so it is regenerated. Because the flaw is actively exploited, review portals for signs of compromise (unexpected accounts, unfamiliar processes or remote access tools) and, for federal agencies, follow the applicable BOD 22-01 required actions. | 9.8 | 94% | KEV |
| moderateon the order of thousands of internet-exposed instances (self-hosted file-sharing/MFT portals, largely at SMBs and MSPs); no public install counts in the… |
Full article398 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Pixel-Perfect Trap: The Surge of SVG-Borne Phishing Attacks
Threat actors misuse Node.js to deliver malware and other malicious payloads
Byte Bandits: How Fake PDF Converters Are Stealing More Than Just Your Documents
Man Helped Chinese Nationals Get Jobs Involving Sensitive US Government Projects
Unmasking the new XorDDoS controller and infrastructure
Malware
Malicious NPM Packages Targeting PayPal Users
New Malware Variant Identified: ResolverRAT Enters the Maze
Nice chatting with you: what connects cheap Android smartphones, WhatsApp and cryptocurrency theft?
BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets
Gorilla, a newly discovered Android malware
Cascading Shadows: An Attack Chain Approach to Avoid Detection and Complicate Analysis
Hacking
Tycoon2FA New Evasion Technique for 2025
CVE-2025-30406 – Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild
Aiding reverse engineering with Rust and a local LLM
Apple fixes two zero-days exploited in targeted iPhone attacks
Task Scheduler– New Vulnerabilities for schtasks.exe
Over 16,000 Fortinet devices compromised with symlink backdoor
Notorious image board 4chan hacked and internal data leaked
Around the World in 90 Days: State-Sponsored Actors Try ClickFix
CVE-2025-24054, NTLM Exploit in the Wild
Intelligence and Information Warfare
Goodbye HTA, Hello MSI: New TTPs and Clusters of an APT driven by Multi-Platform Attacks
Taiwan charges Chinese ship captain with breaking subsea cables
Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware
Renewed APT29 Phishing Campaign Against European Diplomats
Gamaredon: The Turncoat Spies Relentlessly Hacking Ukraine
Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1
Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2
Cybersecurity
Making AI Work Harder for Europeans
Govtech giant Conduent confirms client data stolen in January cyberattack
CISA extends CVE program contract with MITRE for 11 months amid alarm over potential lapse
Google adds Android auto-reboot to block forensic data extractions
Pentagon’s ‘SWAT team of nerds’ resigns en masse
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/176716/breaking-news/security-affairs-newsletter-round-520-by-pierluigi-paganini-international-edition.html