ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 520 by Pierluigi Paganini

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-30406CVE-2025-24054CVE-2021-20035

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-20035
Authenticated OS Command Injection in SonicWall SMA100 Appliances

CVE-2021-20035 is an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the management interface of SonicWall SMA100 series appliances. A remote attacker who has authenticated with low-level privileges can inject arbitrary operating system commands, which are executed on the appliance as the 'nobody' user. Per the CVSS scoring, the primary impact is on availability, potentially leading to denial of service, though command execution on the appliance could facilitate further abuse. The flaw affects SMA 200, 210, 400, 410, and 500v firmware. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-04-16, and related reporting describes ongoing attacks against SonicWall SMA 100 devices — including by threat group UNC6148 deploying the OVERSTEP rootkit and tailored backdoor malware, some against fully patched appliances — so defenders should treat this as actively exploited.

Do: Patch to the fixed firmware release specified in the SonicWall advisory for your SMA model as soon as possible; federal agencies must follow the BOD 22-01 mitigation deadline per the CISA KEV required action. Restrict the management interface to trusted networks, enforce MFA on the portal, and hunt for signs of compromise such as the OVERSTEP rootkit, unexpected persistence, or unfamiliar accounts, since reporting indicates tailored backdoor malware in recent SMA 100 attacks.

6.54% KEV
  • SonicWall SMA 200 firmware
  • SonicWall SMA 210 firmware
  • SonicWall SMA 400 firmware
  • +2 more
large≈ tens of thousands of internet-exposed SMA 100-series appliances (order of magnitude 10k–100k)
CVE-2025-24054
NTLM Hash Disclosure Spoofing Vulnerability in Microsoft Windows

CVE-2025-24054 is a spoofing vulnerability in Microsoft Windows NTLM caused by external control of a file name or path (CWE-73): when Windows processes a file whose name or path points to an attacker-controlled resource, the system is induced to authenticate via NTLM to that destination, disclosing the user's NTLM hash. An unauthorized network attacker triggers the flaw by convincing a user to interact with a crafted file, for example downloading or opening a malicious file, which sends NTLM credentials to a host of the attacker's choosing. With the captured NTLM hash, the attacker can attempt relay or offline cracking to spoof and impersonate the user on the network; no privileges are required, but user interaction is needed (CVSS 3.1: 5.4, medium). Any unpatched Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), or Windows Server 2008, 2012, 2016, or 2019 system in environments that use NTLM authentication is affected. The flaw is being actively exploited: CISA added it to the KEV catalog on 2025-04-17, EPSS puts the 30-day exploitation probability at about 59% (99th percentile), public proof-of-concept exploits exist, and multiple attack campaigns have been reported, including targeting of organizations in Poland and Romania shortly after the patch became available.

Do: Apply Microsoft's April 2025 security updates across all listed Windows 10, Windows 11, and Windows Server releases and confirm updated builds through patch-management reporting; the flaw was added to CISA's KEV on 2025-04-17, so federal agencies must patch per BOD 22-01 deadlines or apply vendor mitigations. As interim mitigation, restrict outbound NTLM authentication (for example by blocking outbound TCP 445/139 to untrusted hosts, enforcing SMB signing, or removing NTLM where feasible) and hunt for anomalous outbound NTLM authentication following user file downloads or opening of untrusted shortcut files.

5.459% KEV PoC ×3
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
masshundreds of millions of Windows devices (desktops and servers on the affected Windows 10, Windows 11, and Windows Server releases with NTLM in use)
CVE-2025-30406
Hard-coded machineKey enables unauthenticated deserialization RCE in Gladinet CentreStack and Triofox

Gladinet CentreStack (and, per CISA, the companion product Triofox) ships with a hard-coded ASP.NET machineKey in the portal's web.config, which is used to protect ViewState and similar serialized data. An attacker who knows this fixed key can craft a serialized payload and submit it to the network-facing portal, where server-side deserialization executes it, yielding unauthenticated remote code execution (CVSS 9.8, no privileges or user interaction required). Successful RCE gives attackers full control of the file-sharing server (high confidentiality, integrity and availability impact); public reporting indicates attackers have abused the flaw to gain unauthorized access and install remote access tools. Anyone running the affected CentreStack builds is exposed, with self-hosted deployments at SMBs and MSP-hosted environments the typical footprint. The flaw was exploited in the wild in March 2025, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-04-08, and carries an EPSS of 94.3% (100th percentile).

Do: Upgrade CentreStack to 16.4.10315.56368 or later, and apply the equivalent vendor fix for Triofox; as an interim mitigation, administrators can delete the hard-coded machineKey defined in portal\web.config so it is regenerated. Because the flaw is actively exploited, review portals for signs of compromise (unexpected accounts, unfamiliar processes or remote access tools) and, for federal agencies, follow the applicable BOD 22-01 required actions.

9.894% KEV
  • Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368)
  • Gladinet Triofox
moderateon the order of thousands of internet-exposed instances (self-hosted file-sharing/MFT portals, largely at SMBs and MSPs); no public install counts in the…
Full article398 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Pixel-Perfect Trap: The Surge of SVG-Borne Phishing Attacks  

Threat actors misuse Node.js to deliver malware and other malicious payloads  

Byte Bandits: How Fake PDF Converters Are Stealing More Than Just Your Documents  

Man Helped Chinese Nationals Get Jobs Involving Sensitive US Government Projects  

Unmasking the new XorDDoS controller and infrastructure

Malware

Malicious NPM Packages Targeting PayPal Users

New Malware Variant Identified: ResolverRAT Enters the Maze      

Nice chatting with you: what connects cheap Android smartphones, WhatsApp and cryptocurrency theft?  

BPFDoor’s Hidden Controller Used Against Asia, Middle East Targets  

Gorilla, a newly discovered Android malware

Cascading Shadows: An Attack Chain Approach to Avoid Detection and Complicate Analysis

Hacking

Tycoon2FA New Evasion Technique for 2025  

CVE-2025-30406 – Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild

Aiding reverse engineering with Rust and a local LLM  

Apple fixes two zero-days exploited in targeted iPhone attacks

Task Scheduler– New Vulnerabilities for schtasks.exe  

Over 16,000 Fortinet devices compromised with symlink backdoor 

Notorious image board 4chan hacked and internal data leaked

Around the World in 90 Days: State-Sponsored Actors Try ClickFix     

CVE-2025-24054, NTLM Exploit in the Wild 

Credential Access Campaign Targeting SonicWall SMA Devices Potentially Linked to Exploitation of CVE-2021-20035  

Intelligence and Information Warfare

Goodbye HTA, Hello MSI: New TTPs and Clusters of an APT driven by Multi-Platform Attacks  

Taiwan charges Chinese ship captain with breaking subsea cables 

Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware

Renewed APT29 Phishing Campaign Against European Diplomats

NSO lawyer names Mexico, Saudi Arabia, and Uzbekistan as spyware customers accused of 2019 WhatsApp hacks  

Gamaredon: The Turncoat Spies Relentlessly Hacking Ukraine 

Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1

Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2       

Cybersecurity

Making AI Work Harder for Europeans 

Govtech giant Conduent confirms client data stolen in January cyberattack  

CISA extends CVE program contract with MITRE for 11 months amid alarm over potential lapse

Google adds Android auto-reboot to block forensic data extractions    

Pentagon’s ‘SWAT team of nerds’ resigns en masse  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/176716/breaking-news/security-affairs-newsletter-round-520-by-pierluigi-paganini-international-edition.html