Skip to main content

Multiple Vulnerabilities in Internet-Facing Systems Targeting Hong Kong’s Education Sector

Release Date: 24 Jul 2026 546 Views

RISK: High Risk

TYPE: Attacks - Other

TYPE: Other

HKCERT has received threat intelligence indicating that threat actors are attempting to target Internet-facing systems of Hong Kong’s education sector by scanning for and exploiting their vulnerabilities. Successful exploitation could result in remote code execution, denial of service condition and security restriction bypass, allowing attackers to deploy web shells and backdoors, steal credentials, establish proxy tunnels and move laterally within affected networks.

 

Note:

CVE-2020-25223 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Sophos SG UTM if the WebAdmin is configured to be accessible to the internet. Hence, the risk level is rated as High Risk.

 

CVE-2020-26919 is being exploited in the wild. NETGEAR JGS516PE devices are affected by missing function level access control vulnerability. Hence, the risk level is rated as High Risk.

 

CVE-2020-7796 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger Server-Side Request Forgery on Zimbra Collaboration Suite (ZCS) if WebEx zimlet is installed and zimlet JSP is enabled. Hence, the risk level is rated as High Risk.

 

CVE-2021-1497 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Cisco HyperFlex HX if the web-based management interface is configured to be accessible to the internet. Hence, the risk level is rated as High Risk.

 

CVE-2021-31755 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Tenda AC11 if remote administration is enabled. Hence, the risk level is rated as High Risk.

 

CVE-2021-36380 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Sunhillo SureLine if the Web GUI is configured to be accessible to the internet. Hence, the risk level is rated as High Risk.

 

CVE-2022-26143 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger denial of service condition on MiCollab and MiVoice Business Express if firewall is disabled. Hence, the risk level is rated as High Risk.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Denial of Service

System / Technologies affected

CVE-2018-11511

  • ASUSTOR ADM versions <= 3.1.0.RFQ3

CVE-2018-16167

  • LogonTracer versions <= 1.2.0

CVE-2018-17254

  • JCK Editor component for Joomla! version = 6.4.4

CVE-2020-25223

  • Sophos SG UTM versions <= v9.705 MR5
  • Sophos SG UTM versions <= v9.607 MR7
  • Sophos SG UTM versions <= v9.511 MR11

CVE-2020-26919

  • NETGEAR JGS516PE versions < 2.6.0.43

CVE-2020-35713

  • Belkin LINKSYS RE6500 versions < 1.0.012.001

CVE-2020-7796

  • Zimbra Collaboration Suite (ZCS) version < 8.8.15 Patch 7

CVE-2021-1498

  • Cisco HyperFlex HX versions < 4.0(2e)
  • Cisco HyperFlex HX versions < 4.5(2a)

CVE-2021-24139

  • Photo Gallery (10Web Photo Gallery) WordPress plugin, versions < 1.5.55

CVE-2021-31755

  • Tenda AC11 versions <= 02.03.01.104_CN

CVE-2021-32305

  • WebSVN versions < 2.6.1

CVE-2021-36380

  • Sunhillo SureLine versions < 8.7.0.1.1

CVE-2022-26143

  • Mitel MiCollab versions < R9.4SP1 & MiVoice Business Express <= R8.1

Solutions

Apply fixes issued by the vendor:

 

CVE-2018-11511

  • ASUSTOR ADM versions > 3.1.0.RFQ3

CVE-2018-16167

  • LogonTracer versions > 1.2.0

CVE-2018-17254

  • JCK Editor component for Joomla! version > 6.4.4

CVE-2020-25223

  • Sophos SG UTM versions > v9.705 MR5
  • Sophos SG UTM versions > v9.607 MR7
  • Sophos SG UTM versions > v9.511 MR11

CVE-2020-26919

  • NETGEAR JGS516PE versions >= 2.6.0.43

CVE-2020-35713

  • Belkin LINKSYS RE6500 versions >= 1.0.012.001

CVE-2020-7796

  • Zimbra Collaboration Suite (ZCS) version >= 8.8.15 Patch 7

CVE-2021-1498

  • Cisco HyperFlex HX versions >= 4.0(2e)
  • Cisco HyperFlex HX versions >= 4.5(2a)

CVE-2021-24139

  • Photo Gallery (10Web Photo Gallery) WordPress plugin, versions >= 1.5.55

CVE-2021-31755

  • Tenda AC11 versions > 02.03.01.104_CN

CVE-2021-32305

  • WebSVN versions >= 2.6.1

CVE-2021-36380

  • Sunhillo SureLine versions >= 8.7.0.1.1

CVE-2022-26143

  • Mitel MiCollab versions < R9.4SP1 & MiVoice Business Express > R8.1

Note:

Organisations are advised to review their externally accessible systems, identify whether any affected products or vulnerable versions are in use, and apply the relevant security patches or mitigation measures.


Vulnerability Identifier


Source


Related Link