CVE Tools

Botnet Hunting for Vulnerabilities in Diagnostic Tools

SANS Internet Storm CenterBy SANS Internet Storm Center3 min read

IncidentDiagnostic tools

Our summary

A botnet has been actively scanning for vulnerabilities in diagnostic tools used by various network devices. Multiple URLs linked to these tools were observed being probed, including those tied to known vulnerabilities like CVE-2024-12856 (Four-Faith routers) and others such as CVE-2020-8949 and CVE-2024-48419. These types of tools are particularly prone to command injection flaws due to improper handling of user inputs when invoking system commands. Experts recommend using safer APIs like Python's subprocess.run over direct shell execution methods to mitigate risks.

Read at SANS Internet Storm Center

Below is the opening; the full story is at SANS Internet Storm Center.

From SANS Internet Storm Center

This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven't noticed before. All of these URLs appear to be associated with diagnostic tools:

URL Count Vulnerability / 1 (simple recon for index page) /apply.cgi 20 CVE-2024-12856 Four-Faith router command injection /cgi-bin/adv_ping.cgi 20 ? /cgi-bin/diagnostic.cgi 20 CVE-2013-7179 Seowon Intech WiMAX SWU-9100 mobile route /cgi-bin/DiagnosticsMsg.cgi 20 ? /cgi-bin/ping.cgi 20   /cgi-bin/system_mgr.cgi 20   /cgi-bin/traceroute.cgi 20   /diag_ping.cgi 20 CVE-2020-8949 (maybe.. slightly different URL) Gocloud devices /goform/diagTool 20 CVE-2024-48419 (maybe..) Edimax Routers /goform/ping 20   /ping_test.cgi 20   /sys_diag.html 20…

Continue at SANS Internet Storm Center

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store