logo

Exploited in the Wild: Critical 9.3 CVSS Flaw Turns Tianxin Systems into Hacker Gateways

ID: d3ba99ed-1ed9-57e5-8ce1-c5543138da9a

STIX ID: report--d3ba99ed-1ed9-57e5-8ce1-c5543138da9a

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical (CVSS 9.3) unauthenticated command-injection bug (CVE-2021-4473) in the Tianxin Internet Behavior Management System Reporter endpoint allows attackers to write PHP web shells via crafted objClass parameters and achieve remote code execution, with Shadowserver reporting active exploitation on 2024-06-01; a firmware update (NACFirmware_4.0.0.7_20210716.180815_topsec_0_basic.bin or later) is available to patch the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.