Security News > 2023 > January > Hackers exploit Cacti critical bug to install malware, open reverse shells

More than 1,600 instances of the Cacti device monitoring tool reachable over the internet are vulnerable to a critical security issue that hackers have already started to exploit.
In early December 2022, a security advisory warned of a critical command injection vulnerability in Cacti that could be exploited without authentication.
Another exploit installed was IRC botnet that opened a reverse shell on the host and instructed it to run port scans.
In a report from Censys attack surface search platform for Internet-connected devices, there are 6,427 Cacti hosts exposed on the web.
The company could count 1,637 Cacti hosts reachable over the web that were vulnerable to CVE-2022-46169, many of them running version 1.1.38 of the monitoring solution, released in April 2021.
Of all Cacti hosts for which Censys could determine the version number, only 26 were running an updated release that was not vulnerable to the critical flaw.
News URL
Related news
- Hackers exploit critical Aviatrix Controller RCE flaw in attacks (source)
- Hackers exploit critical unpatched flaw in Zyxel CPE devices (source)
- Hackers exploit SimpleHelp RMM flaws to deploy Sliver malware (source)
- Hackers exploit KerioControl firewall flaw to steal admin CSRF tokens (source)
- Fake LDAPNightmware exploit on GitHub spreads infostealer malware (source)
- Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners (source)
- Russia-Linked Hackers Target Kazakhstan in Espionage Campaign with HATVIBE Malware (source)
- Python-Based Malware Powers RansomHub Ransomware to Exploit Network Flaws (source)
- Hackers Hide Malware in Images to Deploy VIP Keylogger and 0bj3ctivity Stealer (source)
- Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-05 | CVE-2022-46169 | Incorrect Authorization vulnerability in Cacti Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. | 9.8 |