CVE-2020-9425: rConfig <3.9.4 - Sensitive Information Disclosure

HoneyLabs honeypots recorded 89 probes matching CVE-2020-9425 from 5 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /settings.php

Addresses probing it

Source IPProbesNetworkCountry
45.148.10.18340Techoff Srv LimitedThe Netherlands
195.128.248.3334Virtual Systems LLCUkraine
213.209.159.1758Feo Prest SRLTaiwan
87.120.104.295Sino Worldwide Trading LimitedNorway
87.58.199.1342WebNX, Inc.United States

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited401
AS6698Virtual Systems LLC341
AS208137Feo Prest SRL81
AS211443Sino Worldwide Trading Limited51
AS18450WebNX, Inc.21

Captured requests

  • /settings.php.tmp
  • /settings.php.swp
  • /settings.php.bak
  • /settings.php~

HTTP client fingerprints (JA4H)

  • ge11nn0400_88d30a62b7ad
  • ge11nn0400_cf1edba2959c
  • ge11nn06en_c79eadf4d2aa
  • ge11nn06en_35b65d0b464f

CVE report

CVE report

Open a specific CVE from the CVE tracker.