ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Edimax IC-7100 IP Camera, NAKIVO, and SAP NetWeaver AS Java flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-1316CVE-2024-48248CVE-2017-12637

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-12637
CVE-2017-12637: Directory Traversal File Read in SAP NetWeaver AS Java 7.5

CVE-2017-12637 is an unauthenticated directory traversal flaw (CWE-22) in the scheduler UI endpoint scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS of SAP NetWeaver Application Server Java 7.5. A remote attacker triggers it by inserting dot-dot (../) sequences into the query string of that endpoint, causing the server to read files outside the intended directory. Successful exploitation yields arbitrary file disclosure on the server (e.g., configuration files or credentials), with no authentication or user interaction required, consistent with the CVSS 3.1 score of 7.5 (High, network vector, confidentiality-only impact). Organizations running SAP NetWeaver Application Server Java 7.5 are affected, particularly internet-exposed instances such as SAP Enterprise Portal or Process Integration/Orchestration landscapes. The flaw was exploited in the wild as early as August 2017 and addressed via SAP Security Note 2486657; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, and EPSS currently assigns a 95.1% probability of exploitation within 30 days (100th percentile).

Do: Apply the fix from SAP Security Note 2486657 to affected Application Server Java 7.5 systems; where patching is not yet possible, restrict or block access to the scheduler UI path (scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS) and limit internet exposure of AS Java. Hunt for exploitation by reviewing web logs for dot-dot (../) traversal sequences in query strings targeting that endpoint, and follow CISA BOD 22-01 guidance for cloud services or the KEV required action if mitigations are unavailable.

7.595% KEV
  • SAP NetWeaver Application Server Java 7.5 (as specified in the CVE description; the CISA affected list covers SAP NetWeaver generally, and no other version ranges are provided in the data)
largetens of thousands of SAP AS Java deployments worldwide, with a likely smaller subset (thousands) directly exposed to the internet
CVE-2024-48248
Unauthenticated absolute path traversal file read in NAKIVO Backup & Replication

NAKIVO Backup & Replication before version 11.0.0.88174 contains an absolute path traversal flaw (CWE-36) in the getImageByPath function exposed through the /c/router endpoint, which lets an attacker read arbitrary files from the server. Because the request requires no authentication and no user interaction (CVSS 3.1: 8.6, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), any party that can reach the NAKIVO web interface can send crafted requests to retrieve files. The impact can extend beyond file disclosure: the PhysicalDiscovery function stores credentials in cleartext, so files harvested via the traversal can expose credentials that may enable remote code execution across the enterprise. All organizations running affected versions are at risk, particularly those with the NAKIVO web UI reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-19 amid reports of active exploitation, and EPSS puts its 30-day exploitation probability at roughly 94%.

Do: Upgrade NAKIVO Backup & Replication to version 11.0.0.88174 or later; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance (or discontinue use) within the required timeframe. Until patched, restrict internet exposure of the NAKIVO web interface and /c/router endpoint, review logs for suspicious getImageByPath requests, and rotate credentials configured for PhysicalDiscovery since cleartext credential harvesting may have enabled broader compromise.

8.694% KEV PoC
  • NAKIVO Backup & Replication (Backup & Replication Director) all versions before 11.0.0.88174
moderate≈ tens of thousands of deployments (vendor marketing cites ~30k+ customers; only the subset with the web UI exposed to the internet, likely thousands, are…
CVE-2025-1316
Unauthenticated OS Command Injection RCE in Edimax IC-7100 IP Camera

CVE-2025-1316 is an OS command injection flaw (CWE-78) in the Edimax IC-7100 IP camera that fails to properly neutralize requests it receives. Because the request handling is reachable over the network without authentication or user interaction (per the CVSS 4.0 vector), an unauthenticated attacker can send specially crafted requests to the device. Successful exploitation yields full remote code execution on the camera, with high impact on confidentiality, integrity, and availability of the device itself. Only deployments using the Edimax IC-7100 camera and its firmware are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, and public reporting indicates Mirai-based botnets have been exploiting it since roughly a year before its disclosure, making it effectively a zero-day used to recruit cameras into botnets.

Do: Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the IC-7100 if mitigations are unavailable; check whether Edimax has released updated firmware and install it. In the meantime, reduce exposure by removing any port-forwarding or direct internet access to affected cameras, restricting management interfaces to trusted networks, and monitoring for Mirai-like scanning or traffic. Treat exploitation as likely given the high EPSS (74.5% in 30 days) and in-the-wild botnet use.

9.374% KEV
  • Edimax IC-7100 IP Camera firmware
moderateapproximately 1,000-10,000 internet-exposed devices (estimated)
Full article453 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Edimax IC-7100 IP Camera, NAKIVO, and SAP NetWeaver AS Java flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2025-1316 Edimax IC-7100 IP Camera OS Command Injection Vulnerability
  • CVE-2024-48248 NAKIVO Backup and Replication Absolute Path Traversal Vulnerability
  • CVE-2017-12637 SAP NetWeaver Directory Traversal Vulnerability

In early March, 2025, US CISA warned that multiple botnets are exploiting a recently disclosed vulnerability, tracked as CVE-2025-1316 (CVSS score of 9.8), in Edimax IC-7100 IP cameras.

The issue is an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’. Edimax IC-7100 fails to properly sanitize requests, an attacker can create specially crafted requests to achieve remote code execution on the device. Report suspected malicious activity to CISA for tracking and correlation with other incidents.

The flaw impacts all C-7100 IP Camera versions and has yet to address the vulnerability because these cameras are end-of-life products.

The advisory doesn’t confirm exploitation of the flaw in the wild, however, the USE agency urges organizations to report suspected malicious activity for tracking and correlation.

Akamai researchers discovered the vulnerability, and the cyber security firm confirmed ([1],[2]) that the flaw is actively exploited in the wild.

The experts observed multiple Mirai-based botnets that are currently exploiting multiple flaws, including Edimax IC-7100 IP cameras.

Threat actors exploit remote command execution to run a shell script that downloads a Mirai malware payload from a remote server.

The second flaw added to the catalog, tracked as CVE-2024-48248, is a path traversal issue that allows unauthenticated attackers to read sensitive files like “/etc/shadow” via the “/c/router” endpoint, affecting all versions before 10.11.3.86570.

The vulnerability was patched in November 2024 with version 11.0.0.88174, watchTowr Labs published a proof-of-concept exploit code in February.

The third issue added to the KeV catalog is a directory traversal vulnerability, tracked as CVE-2017-12637, in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5. Remote attackers can exploit the flaw to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by April 9, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/175663/security/u-s-cisa-adds-edimax-ic-7100-ip-camera-nakivo-and-sap-netweaver-as-java-flaws-to-its-known-exploited-vulnerabilities-catalog.html