Exploited in the Wild: Critical 9.3 CVSS Flaw Turns Tianxin Systems into Hacker Gateways
ID: d3ba99ed-1ed9-57e5-8ce1-c5543138da9a
STIX ID: report--d3ba99ed-1ed9-57e5-8ce1-c5543138da9a
Feed Name: securityonline.info
Threat Score
A critical (CVSS 9.3) unauthenticated command-injection bug (CVE-2021-4473) in the Tianxin Internet Behavior Management System Reporter endpoint allows attackers to write PHP web shells via crafted objClass parameters and achieve remote code execution, with Shadowserver reporting active exploitation on 2024-06-01; a firmware update (NACFirmware_4.0.0.7_20210716.180815_topsec_0_basic.bin or later) is available to patch the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
