CVE report
CVE-2021-42013CRITICALKEV
Apache CGI Path Traversal / Self-Rep Payload
Events 90d
1,786
Distinct IPs
768
Severity
CRITICAL
CISA KEV
Actively exploited
Detection signature
An event counts toward CVE-2021-42013 when its URL path contains any of these (case-insensitive). This is what our matching is based on.
- · apache.selfrep
- · /icons/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/etc/passwd
- · /icons/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/etc/passwd
- · /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh
Pre-disclosure activity
all early actors →Analysing probe history around the publication date…
Recent probe volume (last 7 days)
peak: 42 events/dayeventsdistinct IPs
Downloads & integrations
Top sources probing for CVE-2021-42013
- 83.168.106.2642 eventsPoland· SkyPass Solutions Sp. z.o.o.
- 110.35.80.11637 eventsIndonesia· PT. NAP Info Lintas Nusa
- 101.47.8.18735 eventsSingapore· Byteplus Pte. Ltd.
- 31.132.90.332 eventsKazakhstan· Kar-Tel LLC
- 101.36.104.24229 eventsJapan· UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- 185.38.148.228 eventsUnited Kingdom· Hydra Communications Ltd
- 47.253.5.13025 eventsUnited States· Alibaba US Technology Co., Ltd.
- 172.185.40.4715 eventsUnited States· Microsoft Corporation
- 180.76.172.15613 eventsChina· Beijing Baidu Netcom Science and Technology Co., Ltd.
- 202.183.141.13313 eventsThailand· SBN-ISPAWN-ISP and SBN-NIXAWN-NIX
- 89.126.211.16613 eventsUzbekistan· Uzbektelekom Joint Stock Company
- 118.145.104.10513 eventsChina· Beijing Volcano Engine Technology Co., Ltd.
- 41.75.114.3012 eventsMalawi· SKYBAND
- 117.175.140.12112 eventsChina· China Mobile Communications Group Co., Ltd.
- 47.95.234.2311 eventsChina· Hangzhou Alibaba Advertising Co.,Ltd.
- 216.57.110.8111 eventsHong Kong
- 5.175.169.6311 eventsGermany· TeraSwitch Networks Inc.
- 81.226.129.6711 eventsSweden· Telia Company AB
- 47.85.8.17110 eventsUnited States· Alibaba US Technology Co., Ltd.
- 189.51.43.5410 eventsBrazil· INOVE TELECOMUNICACOES E SERVICOS LTDA
- 212.127.91.3210 eventsPoland· Korbank S. A.
- 125.20.210.18210 eventsIndia· BHARTI Airtel Ltd.
- 79.76.58.11310 eventsSweden· Oracle Corporation
- 118.26.111.1079 eventsSingapore· UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- 199.21.150.1059 eventsCanada· Netminders Server Hosting
- 115.191.32.579 eventsChina· Beijing Volcano Engine Technology Co., Ltd.
- 152.32.226.2059 eventsHong Kong· UCLOUD INFORMATION TECHNOLOGY HK LIMITED
- 46.191.157.1599 eventsRussia· JSC Ufanet
- 120.48.32.1309 eventsChina· Beijing Baidu Netcom Science and Technology Co., Ltd.
- 83.229.8.1979 eventsItaly· Convergenze S.p.A.
Top networks the attempts come from
- AS45102 Alibaba US Technology Co., Ltd.50 IPs · 119 ev
- AS51167 Contabo GmbH56 IPs · 90 ev
- AS135377 UCLOUD INFORMATION TECHNOLOGY HK LIMITED14 IPs · 85 ev
- AS9808 China Mobile Communications Group Co., Ltd.26 IPs · 75 ev
- AS150436 Byteplus Pte. Ltd.5 IPs · 60 ev
- AS137718 Beijing Volcano Engine Technology Co., Ltd.16 IPs · 53 ev
- AS14061 DigitalOcean, LLC28 IPs · 43 ev
- AS202520 SkyPass Solutions Sp. z.o.o.2 IPs · 43 ev
- AS17727 PT. NAP Info Lintas Nusa1 IPs · 37 ev
- AS37963 Hangzhou Alibaba Advertising Co.,Ltd.21 IPs · 37 ev
Fingerprints of the clients exploiting this
The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.
Sample request paths observed
- /icons/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/etc/passwd
- /icons/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/etc/passwd
- /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh