logo

CVE-2019-19781: Analyzing the Exploit

ID: 4a1881d0-c290-5d85-923f-d96f8d1b9685

STIX ID: report--4a1881d0-c290-5d85-923f-d96f8d1b9685

Feed Name: ReliaQuest Blog

Threat Score
80/100

Date Published: 2020-01-14

Date Updated: 2026-04-29

...
...

This report documents active exploitation of Citrix ADC/Gateway CVE-2019-19781: a directory traversal vulnerability enabling remote code execution. The author verified the exploit in AWS (obtaining an nsroot reverse shell), deployed a honeypot that observed heavy scanning and multiple exploit attempts (127,085 GETs in 48 hours, 249 exploitation attempts), and identified indicators including malicious curl URLs, many attacker IPs, and evidence of a cryptominer/backdoor. Mitigations and CISA/patch guidance are referenced.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.