Multiple Vulnerabilities in Internet-Facing Systems Targeting Hong Kong’s Education Sector
RISK: High Risk
TYPE: Attacks - Other

HKCERT has received threat intelligence indicating that threat actors are attempting to target Internet-facing systems of Hong Kong’s education sector by scanning for and exploiting their vulnerabilities. Successful exploitation could result in remote code execution, denial of service condition and security restriction bypass, allowing attackers to deploy web shells and backdoors, steal credentials, establish proxy tunnels and move laterally within affected networks.
Note:
CVE-2020-25223 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Sophos SG UTM if the WebAdmin is configured to be accessible to the internet. Hence, the risk level is rated as High Risk.
CVE-2020-26919 is being exploited in the wild. NETGEAR JGS516PE devices are affected by missing function level access control vulnerability. Hence, the risk level is rated as High Risk.
CVE-2020-7796 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger Server-Side Request Forgery on Zimbra Collaboration Suite (ZCS) if WebEx zimlet is installed and zimlet JSP is enabled. Hence, the risk level is rated as High Risk.
CVE-2021-1497 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Cisco HyperFlex HX if the web-based management interface is configured to be accessible to the internet. Hence, the risk level is rated as High Risk.
CVE-2021-31755 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Tenda AC11 if remote administration is enabled. Hence, the risk level is rated as High Risk.
CVE-2021-36380 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger remote code execution on Sunhillo SureLine if the Web GUI is configured to be accessible to the internet. Hence, the risk level is rated as High Risk.
CVE-2022-26143 is being exploited in the wild. A remote attacker could exploit this vulnerability to trigger denial of service condition on MiCollab and MiVoice Business Express if firewall is disabled. Hence, the risk level is rated as High Risk.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Denial of Service
System / Technologies affected
CVE-2018-11511
- ASUSTOR ADM versions <= 3.1.0.RFQ3
CVE-2018-16167
- LogonTracer versions <= 1.2.0
CVE-2018-17254
- JCK Editor component for Joomla! version = 6.4.4
CVE-2020-25223
- Sophos SG UTM versions <= v9.705 MR5
- Sophos SG UTM versions <= v9.607 MR7
- Sophos SG UTM versions <= v9.511 MR11
CVE-2020-26919
- NETGEAR JGS516PE versions < 2.6.0.43
CVE-2020-35713
- Belkin LINKSYS RE6500 versions < 1.0.012.001
CVE-2020-7796
- Zimbra Collaboration Suite (ZCS) version < 8.8.15 Patch 7
CVE-2021-1498
- Cisco HyperFlex HX versions < 4.0(2e)
- Cisco HyperFlex HX versions < 4.5(2a)
CVE-2021-24139
- Photo Gallery (10Web Photo Gallery) WordPress plugin, versions < 1.5.55
CVE-2021-31755
- Tenda AC11 versions <= 02.03.01.104_CN
CVE-2021-32305
- WebSVN versions < 2.6.1
CVE-2021-36380
- Sunhillo SureLine versions < 8.7.0.1.1
CVE-2022-26143
- Mitel MiCollab versions < R9.4SP1 & MiVoice Business Express <= R8.1
Solutions
Apply fixes issued by the vendor:
CVE-2018-11511
- ASUSTOR ADM versions > 3.1.0.RFQ3
CVE-2018-16167
- LogonTracer versions > 1.2.0
CVE-2018-17254
- JCK Editor component for Joomla! version > 6.4.4
CVE-2020-25223
- Sophos SG UTM versions > v9.705 MR5
- Sophos SG UTM versions > v9.607 MR7
- Sophos SG UTM versions > v9.511 MR11
CVE-2020-26919
- NETGEAR JGS516PE versions >= 2.6.0.43
CVE-2020-35713
- Belkin LINKSYS RE6500 versions >= 1.0.012.001
CVE-2020-7796
- Zimbra Collaboration Suite (ZCS) version >= 8.8.15 Patch 7
CVE-2021-1498
- Cisco HyperFlex HX versions >= 4.0(2e)
- Cisco HyperFlex HX versions >= 4.5(2a)
CVE-2021-24139
- Photo Gallery (10Web Photo Gallery) WordPress plugin, versions >= 1.5.55
CVE-2021-31755
- Tenda AC11 versions > 02.03.01.104_CN
CVE-2021-32305
- WebSVN versions >= 2.6.1
CVE-2021-36380
- Sunhillo SureLine versions >= 8.7.0.1.1
CVE-2022-26143
- Mitel MiCollab versions < R9.4SP1 & MiVoice Business Express > R8.1
Note:
Organisations are advised to review their externally accessible systems, identify whether any affected products or vulnerable versions are in use, and apply the relevant security patches or mitigation measures.
Vulnerability Identifier
- CVE-2018-11511
- CVE-2018-16167
- CVE-2018-17254
- CVE-2020-7796
- CVE-2020-25223
- CVE-2020-26919
- CVE-2020-35713
- CVE-2021-1498
- CVE-2021-24139
- CVE-2021-31755
- CVE-2021-32305
- CVE-2021-36380
- CVE-2022-26143
Source
- https://www.group-ib.com
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://jvn.jp
- https://nvd.nist.gov
- https://community.sophos.com
- https://kb.netgear.com
- https://downloads.linksys.com
- https://wiki.zimbra.com
- https://www.sunhillo.com
- https://www.mitel.com
Related Link
- https://www.group-ib.com/blog/jadeprox-china-nexus-triback-loader/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2018-11511
- https://jvn.jp/en/vu/JVNVU98026636/index.html
- https://nvd.nist.gov/vuln/detail/CVE-2018-17254
- https://community.sophos.com/b/security-blog/posts/advisory-resolved-rce-in-sg-utm-webadmin-cve-2020-25223
- https://kb.netgear.com/000062334/Security-Advisory-for-Missing-Function-Level-Access-Control-on-JGS516PE-PSV-2020-0377
- https://downloads.linksys.com/support/assets/releasenotes/ExternalReleaseNotes_RE6500_1.0.012.001.txt
- https://wiki.zimbra.com/wiki/Zimbra_Releases/8.8.15/P7
- https://nvd.nist.gov/vuln/detail/CVE-2021-24139
- https://nvd.nist.gov/vuln/detail/cve-2021-31755
- https://nvd.nist.gov/vuln/detail/CVE-2021-32305
- https://www.sunhillo.com/fb011/
- https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0001
Related Tags
Share with
