Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20166 +1 in the same advisory: …20167 | Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the applicaiton. NVD description · AI analysis pending | 8.8 group max | 2% |
| — | ||
| CVE-2021-21881 | An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. NVD description · AI analysis pending | 9.9 | 36% | PoC |
| — | |
| CVE-2021-24762 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_questi The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection. NVD description · AI analysis pending | 9.8 | 87% | PoC ×2 |
| — | |
| CVE-2021-28169 | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected reso For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application. NVD description · AI analysis pending | 5.3 | 78% |
| — | ||
| CVE-2021-31589 | A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which all A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization. NVD description · AI analysis pending | 6.1 | 29% | PoC ×2 |
| — | |
| CVE-2021-39226 | Authentication Bypass in Grafana Exposes and Deletes Dashboard Snapshot Data Grafana contains an authentication bypass (CWE-287) in its handling of dashboard snapshot data, allowing both authenticated and unauthenticated users to access snapshot endpoints without proper authorization. An attacker can trigger the flaw by sending crafted requests to the snapshot API without valid credentials. Successful exploitation lets the attacker view and delete all snapshot data, potentially resulting in complete loss of saved snapshots, which may destroy evidence of historical dashboard state. Any organization running an affected Grafana release from Grafana Labs is exposed, particularly instances reachable by untrusted users. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2022-08-25 and carries a 99.9% EPSS probability of exploitation within 30 days. Do: Apply updates per vendor instructions: upgrade Grafana to a patched release per the Grafana Labs advisory for CVE-2021-39226 and prioritize patching internet-facing instances given KEV listing. As an interim mitigation, restrict unauthenticated access to the snapshot API (e.g., via reverse-proxy access rules) and verify whether snapshots have been viewed or deleted on your instances. | 7.3 | 100% | KEV PoC |
| masslikely >100,000 internet-exposed Grafana instances, with many more deployed internally | |
| CVE-2021-4045 | TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera. NVD description · AI analysis pending | 9.8 | 72% | PoC |
| — | |
| CVE-2021-43711 | The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution. NVD description · AI analysis pending | 9.8 | 38% | PoC |
| — | |
| CVE-2022-21371 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). NVD description · AI analysis pending | 7.5 | 93% | PoC |
| — | |
| CVE-2022-21662 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue. NVD description · AI analysis pending | 5.4 | 65% |
| — | ||
| CVE-2022-22536 | HTTP Request Smuggling in SAP NetWeaver, Web Dispatcher and Content Server CVE-2022-22536 (CWE-444) is an HTTP request smuggling and request concatenation flaw in the Internet Communication Manager components of SAP NetWeaver Application Server ABAP and Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher. An unauthenticated remote attacker sends crafted HTTP requests whose framing is interpreted inconsistently by intermediary and back-end components, allowing arbitrary attacker-controlled data to be prepended to a victim's request. This lets the attacker execute functions impersonating the victim or poison intermediary web caches, and a successful attack could result in complete compromise of the confidentiality, integrity and availability of the system (CVSS 10.0). Any organization running the affected SAP components is exposed, especially internet-facing SAP systems and those fronted by reverse proxies or caches where front-end/back-end parsing differs. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-08-18 and EPSS assigns a 97.9% probability of exploitation within 30 days, although no public PoC is known and ransomware use is unconfirmed. Do: Apply SAP's security updates per vendor instructions for CVE-2022-22536 (SAP Note 3123396), prioritizing internet-facing Web Dispatcher, ICM/NetWeaver and Content Server 7.53 systems as required by the CISA KEV listing. Until patched, restrict direct HTTP access to affected SAP components, review front-end proxies/caches for HTTP framing mismatches, and monitor for anomalous request concatenation or impersonation. Ransomware linkage is unknown, so treat this as general web-application exploitation risk. | 10.0 | 98% | KEV |
| mass≈100,000+ SAP systems globally (large-enterprise installed base; tens of thousands internet-exposed) | |
| CVE-2022-22947 | Unauthenticated RCE in VMware Spring Cloud Gateway CVE-2022-22947 is a code injection (Spring Expression Language injection) flaw in VMware Spring Cloud Gateway that allows arbitrary remote code execution when the Gateway Actuator endpoint is enabled, exposed, and unsecured. A remote, unauthenticated attacker can send a maliciously crafted request (typically a crafted POST to the gateway actuator routes endpoint) that is evaluated as code, letting the attacker run arbitrary commands on the host. The CVSS 3.1 score is 10.0 (critical) because exploitation is network-based, requires no privileges or user interaction, and impacts confidentiality, integrity, and availability beyond the vulnerable component. All Spring Cloud Gateway deployments prior to 3.1.1/3.0.7 are affected, along with Oracle products that embed the component, including Commerce Guided Search and multiple Oracle Communications Cloud Native Core functions. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-16, EPSS puts the 30-day exploitation probability at 98.3% (100th percentile), public PoC exploits exist, and related reporting describes botnets adding Spring Cloud Gateway exploits to their attack tooling. Do: Upgrade Spring Cloud Gateway to 3.1.1 or later, or to 3.0.7 or later on the 3.0.x line, per VMware's advisory, and apply the relevant Oracle Critical Patch Update for affected Oracle Commerce Guided Search and Communications Cloud Native Core products. If you cannot patch immediately, disable or restrict the Gateway Actuator endpoint so it is not reachable over the network without authentication. Scan for exposed gateway actuator endpoints and review hosts for signs of command execution; this flaw is on CISA's KEV list, which requires applying updates per vendor instructions. | 10.0 | 98% | KEV PoC ×2 |
| large≈ tens of thousands of deployments plausibly affected worldwide, with only the subset exposing the actuator endpoint unauthenticated directly exploitable from… | |
| CVE-2022-22954 | Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2022-22954 is a server-side template injection vulnerability (CWE-94) in VMware Workspace ONE Access and VMware Identity Manager that allows remote code execution on affected appliances. It is triggered when attacker-controlled input is passed into a server-side template engine, allowing injected template directives to be evaluated and executed as code on the server. A successful attacker gains the ability to run arbitrary code on the identity appliance, and CISA notes the flaw has been used in ransomware campaigns, so compromise can serve as an initial foothold for broader enterprise intrusion. Any organization running Workspace ONE Access or Identity Manager, including deployments where the Identity Manager component is bundled into VMware Horizon environments, is potentially affected, though the source data does not specify affected version ranges. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-14 with ransomware use confirmed and a required action to apply vendor updates, and EPSS currently assigns it a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known. Do: Apply the patches published in VMware advisory VMSA-2022-0011 (April 2022) to Workspace ONE Access and Identity Manager appliances as required by the CISA KEV listing, prioritizing internet-facing instances, and restrict or remove public exposure until patched. Review appliance and web-server logs for template-injection probes and unexpected processes spawned by the identity service, and investigate any indications of compromise for follow-on ransomware or lateral-movement activity. | 9.8 | 100% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Workspace ONE Access / Identity Manager instances (order-of-magnitude estimate; exact count unknown) | |
| CVE-2022-22963 | SpEL Expression Injection RCE in VMware Tanzu Spring Cloud Function VMware Tanzu's Spring Cloud Function contains a remote code execution flaw (CWE-94, expression-language code injection) in its routing functionality. When the routing feature evaluates an attacker-supplied Spring Expression Language (SpEL) routing-expression, a specially crafted expression is processed by the framework, resulting in arbitrary code execution on the server and access to local resources. Any deployment of Spring Cloud Function that evaluates untrusted routing-expressions, typically via exposed application endpoints, is affected. An attacker who can reach such an endpoint gains code execution in the context of the running application, which can lead to data theft, lateral movement, or ransomware. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-08-25 and EPSS rates the 30-day exploitation probability at 99.9% (100th percentile), although no public PoC is cataloged in this data. Do: Apply the vendor update per VMware/Tanzu instructions immediately, as patching is the required action for this KEV-listed vulnerability. Until patched, prevent untrusted clients from supplying the routing-expression (restrict or disable the routing functionality) and limit network exposure of affected services. Review application logs for unexpected SpEL payloads in routing-expressions and check affected hosts for indicators of compromise, including ransomware staging. | 9.8 | 100% | KEV PoC |
| largeplausibly tens of thousands of deployments (10,000-100,000 systems); exact installed base unpublished | |
| CVE-2022-22965 | Unauthenticated RCE in VMware Spring Framework (Spring4Shell) - JDK 9+ Tomcat WARs CVE-2022-22965 ('Spring4Shell') is a critical (CVSS 9.8) remote code execution flaw in VMware's Spring Framework, caused by insecure data binding that lets unauthenticated attackers overwrite internal class and module properties through crafted request parameters (CWE-94, code injection). It affects Spring MVC and Spring WebFlux applications running on JDK 9 or later; the demonstrated exploit path requires a Tomcat WAR deployment, while applications packaged as Spring Boot executable jars are not exploitable that way, though the underlying issue may be reachable via other routes. A successful attack yields full remote code execution with the privileges of the application server, with no authentication or user interaction required. VMware Spring Framework 5.3.0-5.3.17 and 5.2.0-5.2.19 (plus older releases) are affected, and the flaw also impacts bundled products from Cisco, Oracle, Siemens and Veritas, including multiple Oracle Communications Cloud Native Core components. It is being actively exploited in the wild: added to CISA's KEV on 2022-04-04, EPSS puts 30-day exploitation probability at 99.6% (100th percentile), a public PoC is available, and mass scanning of vulnerable servers has been observed. Do: Upgrade Spring Framework to 5.3.18, 5.2.20 or later (or apply vendor-supplied fixes for bundled products, e.g., via Oracle's patch release and Cisco's advisory), prioritizing internet-facing Tomcat WAR deployments on JDK 9+; this is a CISA KEV entry, so treat patching as urgent. If patching must wait, mitigate by running on JDK 8, deploying as a Spring Boot executable jar rather than a WAR on Tomcat, and applying the vendor-documented workaround that disallows 'class.*', 'Class.*' and 'module.*' fields in data binding. Inventory exposed Tomcat/Spring services and hunt for signs of exploitation given confirmed in-the-wild use. | 9.8 | 100% | KEV PoC |
| massmass - on the order of 1M+ Spring-based Java deployments overall, with at least ~100,000 internet-exposed Tomcat servers on JDK 9+ plausibly meeting the… | |
| CVE-2022-24112 | Authentication Bypass Leading to RCE in Apache APISIX CVE-2022-24112 is a client IP validation flaw (CWE-290) in the batch-requests plugin of Apache APISIX: the plugin is supposed to override the client IP with the real remote IP, but due to a coding bug this check can be bypassed, allowing an attacker to send requests that evade the IP restrictions protecting the Admin API. A remote, unauthenticated attacker sends crafted requests through the batch-requests endpoint to reach the otherwise IP-restricted Admin API or data panel. With a default APISIX configuration (default admin API key), this grants access that leads directly to remote code execution; if the admin key was changed or the Admin API runs on a different port, the attacker still gains unauthorized access to the data panel. Any deployment of Apache APISIX is affected, with default or minimally-hardened configurations facing the highest risk. The vulnerability is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-25, carries a 96% EPSS probability of exploitation within 30 days, and public proof-of-concept exploits are available. Do: Upgrade Apache APISIX to the latest patched release per vendor instructions, prioritizing internet-facing instances since active exploitation is confirmed. As immediate mitigation, change the default admin API key, restrict access to the Admin API and data panel, and avoid exposing the Admin API port alongside the data panel. Check logs for anomalous requests to the batch-requests endpoint and Admin API routes indicating exploitation attempts. | 9.8 | 96% | KEV PoC ×2 |
| moderate≈ a few thousand internet-exposed Apache APISIX instances (total installed base higher, including internal/embedded gateway deployments) | |
| CVE-2022-24260 | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level. NVD description · AI analysis pending | 9.8 | 50% | PoC |
| — | |
| CVE-2022-25060 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing. NVD description · AI analysis pending | 9.8 | 40% | PoC |
| — | |
| CVE-2022-25075 | TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter. NVD description · AI analysis pending | 9.8 | 56% | PoC |
| — | |
| CVE-2022-25134 | A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to exe A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet. NVD description · AI analysis pending | 9.8 | 3% |
| — | ||
| CVE-2022-27226 | A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution, allowing the threat actor to gain filesystem access. In addition, if the router's default credentials aren't rotated or a threat actor discovers valid credentials, remote code execution can be achieved without user interaction. NVD description · AI analysis pending | 8.8 | 34% | PoC ×3 |
| — | |
| CVE-2022-29464 | Unrestricted file upload leading to unauthenticated RCE in multiple WSO2 products CVE-2022-29464 is an unrestricted file upload flaw (CISA classifies it as CWE-22, path traversal) in multiple WSO2 products — including WSO2 API Manager, Identity Server (and its Analytics and as-Key-Manager variants), and Enterprise Integrator — that lets an attacker write arbitrary files, such as JSP webshells, to any location on the server. It is triggered by sending crafted multipart upload requests to the WSO2 Carbon management-console file-upload endpoints, where directory traversal in the upload path allows files to be planted in the web root; requesting the uploaded file then executes it as code. An attacker who can reach a vulnerable management console gains unauthenticated remote code execution with the privileges of the WSO2 server process, which is often root in containerized deployments, enabling webshells, lateral movement, and ransomware staging. Any organization running affected WSO2 releases is exposed, especially where Identity Server (SSO/IAM) or API Manager gateways are internet-facing; the exact affected version ranges are enumerated in the WSO2 vendor advisory. Exploitation is confirmed: CISA added the flaw to the KEV catalog on 2022-04-25 with known ransomware use, and EPSS assigns a roughly 100% probability of exploitation within 30 days, making patching urgent. Do: Apply the WSO2 updates/patches listed in the WSO2 security advisory for CVE-2022-29464 (or upgrade to the fixed releases named there), per CISA's required action, and limit internet exposure of Carbon management consoles in the meantime. Because ransomware groups have exploited this flaw, hunt for compromise: check web roots for unexpected JSP files or webshells and review access logs for suspicious file-upload requests followed by GETs to uploaded files. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largeon the order of tens of thousands of internet-exposed WSO2 management consoles (roughly 10,000–100,000 systems); total deployments including internal installs… |
Full article2,409 words · extracted from unit42.paloaltonetworks.com · click to collapse
Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use of newly published remote code execution vulnerabilities in VMware ONE Access and Identity Manager and Spring Cloud Function, Spring MVC and Spring Web Flux, among others. Attackers have also been taking advantage of a cross-site scripting vulnerability in WordPress core, and SQL injection vulnerabilities in VoIPmonitor GUI and other services. In our observations of network security trends, Unit 42 researchers select exploits of the latest published attacks that defenders should know based on the availability of proofs of concept (PoCs), the severity of the vulnerabilities the exploits are based on and the ease of exploitation.
Other insights that could assist defenders include our rankings of the most commonly used techniques and the types of vulnerabilities that attackers have recently favored. For example, among 6,000 newly published vulnerabilities, a large portion (almost 13.3%) involve cross-site scripting, suggesting that defenders may wish to consider how best to mitigate this technique across internet-facing properties.
Other major focuses identified by evaluating more than 93 million attack sessions include remote code execution, traversal and information disclosure.
Additionally, we provide insight into how these vulnerabilities are actively exploited in the wild based on real-world data collected from Palo Alto Networks Next-Generation Firewalls. For example, we highlight how frequently the most commonly exploited vulnerabilities were attacked through networks and the locations from which the attacks appeared to originate. We then draw conclusions about the most commonly exploited vulnerabilities attackers are using, as well as the severity, category and origin of each attack.
Here, we summarize key trends from February-April 2022. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity distribution. We also classify vulnerabilities to provide a clear view of the prevalence of, say, cross-site scripting or denial-of-service.
Palo Alto Networks customers receive protections from the vulnerabilities discussed here through the Next-Generation Firewall and Cloud-Delivered Security Services, including Threat Prevention, WildFire and Advanced URL Filtering, as well as through Cortex XDR.
| CVEs Discussed | CVE-2022-22954, CVE-2022-22963, CVE-2022-22965, CVE-2022-25060, CVE-2022-22947, CVE-2022-24112, CVE-2022-22536, CVE-2021-24762, CVE-2022-21662, CVE-2021-43711, CVE-2022-25075, CVE-2022-25134, CVE-2021-4045, CVE-2022-24260, CVE-2021-21881, CVE-2021-39226, CVE-2021-28169, CVE-2021-20167, CVE-2021-20166, CVE-2022-21371, CVE-2021-31589, CVE-2022-29464, CVE-2022-27226 |
| Types of Attacks and Vulnerabilities Covered | Cross-site scripting, denial of service, information disclosure, buffer overflow, privilege escalation, memory corruption, code execution, SQL injection, out-of-bounds read, cross-site request forgery, directory traversal, command injection, improper authentication, security feature bypass |
| Related Unit 42 Topics | Network Security Trends, exploits in the wild, attack analysis |
Updated Sept. 2 at 12:30 p.m. PT to remove two CVEs that were listed in error.
Analysis of Published Vulnerabilities, February 2022 to April 2022
From February-April 2022, a total of 5,962 new Common Vulnerabilities and Exposures (CVE) numbers were registered. To better understand the potential impact these newly published vulnerabilities could have on network security, we provide our observations based on the severity, proof-of-concept code feasibility and vulnerability categories.
How Severe Are the Latest Vulnerabilities?
To estimate the potential impact of vulnerabilities, we consider their severity and examine any reliable proofs of concept (PoCs) available that attackers could easily launch. Some of the public sources we use to find PoCs are Exploit-DB, GitHub and Metasploit. Distribution of the 5,631 CVEs that have an assigned severity score of medium or higher can be seen in the following table:
| Severity | Count | Ratio | PoC Availability |
| Critical | 1033 | 18.3% | 7.8% |
| High | 2282 | 40.5% | 4.8% |
| Medium | 2316 | 41.1% | 3.6% |
Table 1. Severity distribution for CVEs registered February-April 2022.

Vulnerabilities classified as critical are the least common but are also more likely to have PoCs available. The data suggests a correlation between the availability of a PoC and the severity of a vulnerability. In the period discussed, the critical-severity ratios increased while high-severity and medium-severity PoC ratios decreased slightly. Palo Alto Networks continues to leverage threat intelligence of the latest vulnerabilities and real-time monitoring of exploits in the wild to provide protections for our customers.
Vulnerability Category Distribution
The type of vulnerability is also crucial to understanding its consequences. Out of the newly published CVEs that were analyzed, 26.4% are classified as local vulnerabilities, requiring prior access to compromised systems, while the remaining 73.6% are remote vulnerabilities, which can be exploited over a network. This means that the majority of newly published vulnerabilities introduce potential opportunities for threat actors to attack vulnerable organizations from anywhere in the world.
As shown in Figure 2, we can see the most common vulnerability types ranked by how prevalent they were among the most recent set of published vulnerabilities.

Cross-site scripting remains the most reported vulnerability in this time period, and we also saw an increase in out-of-bounds write and information disclosure vulnerabilities published compared to last quarter. However, most of the recently published cross-site scripting and information disclosure attacks are usually at medium or high severity (rather than critical). At the same time, the prevalence of SQL injection vulnerabilities increased in February-April 2022 – and many of the vulnerabilities in this category are critical.
Network Security Trends: Analysis of Exploits in the Wild, February-April 2022
Data Collection
By leveraging Palo Alto Networks Next-Generation Firewalls as sensors on the perimeter, Unit 42 researchers observed malicious activities from February-April 2022. The malicious traffic we identified is further processed and based on metrics such as IP addresses, port numbers and timestamps. This ensures the uniqueness of each attack session and thus eliminates potential data skews. We analyzed 93 million valid malicious sessions and then correlated the refined data with other attributes to infer attack trends over time to get a picture of the threat landscape.
How Severe Were the Attacks Exploited in the Wild?
To arrive at 93 million valid malicious sessions, we excluded the original set of low-severity signature triggers that are used to detect scanning and brute-force attacks, as well as internal triggers used for research purposes. Therefore, we consider exploitable vulnerabilities with a severity ranking of medium and higher (based on the CVSS v3 Score) as a verified attack.

Figure 3 shows the session count and ratio of attacks grouped by the severity of each vulnerability. Compared with the previous quarters’ severity distribution, this quarter shows almost no difference for critical-, high- and medium-severity attacks. However, we still focus more on critical-severity attacks because of their greater potential impact. Many published vulnerabilities are scored medium severity, but attackers typically leverage more severe vulnerabilities for exploits. Defenders should pay attention to preventing and mitigating high- and critical-severity network attacks.
When Did the Network Attacks Occur?

For this installment of our network security trends analysis, we collected data from February-April 2022. Attackers steadily leveraged high-severity exploits throughout this period.
As we’ve seen in the past, attackers frequently used vulnerabilities disclosed recently, especially those from 2021-22. This shows the importance of updating security products and applying software patches as soon as they become available to protect against the most recently discovered vulnerabilities.

Exploits in the Wild, February-April 2022: A Detailed View
Among the latest published attacks, the following exploits stood out due to their PoC availability, severity and ease of exploitation. We have provided snippets showing how attackers used open source tools to compromise the different targets, allowing defenders to better understand how the exploit operates.
VMware Workspace ONE Access and Identity Manager contain a remote code execution (RCE) vulnerability due to server-side template injection. A malicious actor can trigger a server-side template injection.

In Spring Cloud Function, when using routing functionality, it is possible for a user to provide a specially crafted SpEL as a routing expression that may result in remote code execution and access to local resources.

A Spring MVC or Spring WebFlux application may be vulnerable to RCE via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment.

TP-LINK was discovered to contain a command injection vulnerability via the component oal_startPing.

In Spring Cloud Gateway, applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker can craft a malicious request that would allow arbitrary remote execution on the remote host.

An attacker can abuse the batch requests plugin to send requests and bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to RCE.

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request using arbitrary data.

The Perfect Survey WordPress plugin does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

Low-privileged authenticated users in WordPress core are able to execute JavaScript/perform stored cross-site scripting attacks, which can affect high-privileged users.

CVE-2021-43711, CVE-2022-25075
The downloadFlile.cgi binary file in TOTOLINK has a command injection vulnerability when receiving GET parameters. The parameter name can be constructed for unauthenticated command execution.

A command injection vulnerability in the function setUpgradeFW of the TOTOLINK Technology router allows attackers to execute arbitrary commands.

TP-Link Tapo C200 IP camera is affected by an unauthenticated RCE vulnerability, which is present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.

A SQL injection vulnerability in VoIPmonitor GUI allows an attacker to escalate privileges to the Administrator level.

An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave. A specially crafted HTTP request can lead to command execution. An attacker can then make an authenticated HTTP request to trigger this vulnerability.

There is an easily exploitable vulnerability in the Oracle WebLogic Server that allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.

A cross-site request forgery (CSRF) issue in /api/crontab on iRZ Mobile Routers allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to RCE and allowing the threat actor to gain file system access.

Certain WSO2 products allow unrestricted file upload with resultant RCE. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory.

Other active CVEs we observed this quarter:
- CVE-2021-20167, CVE-2021-20166 – Netgear RAX43 command injection vulnerabilities.
- CVE-2021-39226 – Grafana Labs Grafana Snapshot authentication bypass vulnerability.
- CVE-2021-28169 – Eclipse Jetty information disclosure vulnerability.
- CVE-2021-31589 – BeyondTrust remote support cross-site scripting vulnerability.
Attack Category Distribution
We classified each network attack by category and organized them in terms of prevalence. In the period discussed, RCE ranks first, followed by traversal attacks. Attackers typically want to gain as much information and control as possible over the systems they target. Information disclosure attacks decreased this quarter.

Where Did the Attacks Originate?
After identifying the region from which each network attack originated, we discovered that the majority of them seem to originate from the United States, followed by Germany and Russia. However, we recognize that the attackers might leverage proxy servers and VPNs located in those countries to hide their actual physical locations.


Conclusion
The vulnerabilities disclosed from February-April 2022 indicate that web applications remain popular targets for attackers, and that critical vulnerabilities are more likely to have PoCs publicly available. In the meantime, we continue to capture newly published vulnerabilities that are exploited in the wild. This emphasizes the need for organizations to promptly patch their systems and implement security best practices. If not, attackers will continue to make a concerted effort to expand their arsenal of exploits whenever possible.
While cybercriminals will never cease their malicious activities, Palo Alto Networks customers receive protections from the attacks discussed in this blog through the Next-Generation Firewall and Cloud-Delivered Security Services, including Threat Prevention, WildFire and Advanced URL Filtering, as well as through Cortex XDR.
To further mitigate any risks to your network:
- Run a Best Practice Assessment to identify where your configuration could be altered to improve your security posture.
- Run a Security Lifecycle Review to get a consolidated view of your largest threats and if you have coverage to prevent them.
- Continuously update your Next-Generation Firewalls with the latest Palo Alto Networks Threat Prevention content (e.g. versions 8607 and above).
Additional Resources
- Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
- Network Security Trends: November 2021 to January 2022
- Network Security Trends: August-October 2021
- Network Security Trends: May-July 2021
- Network Attack Trends: February-April 2021
Updated Sept. 2 at 12:30 p.m. PT to remove a CVE that was listed in error.
Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/