CVE-2021-42013: Apache CGI Path Traversal / Self-Rep Payload
HoneyLabs honeypots recorded 78 probes matching CVE-2021-42013 from 56 distinct source IP addresses in the last 7 days. Severity is rated CRITICAL.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- apache.selfrep
- /icons/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/etc/pass…
- /icons/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/etc/passwd
- /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 31.132.90.3 | 6 | Kar-Tel LLC | Kazakhstan |
| 138.2.102.66 | 4 | Oracle Corporation | Singapore |
| 171.244.14.216 | 3 | CHT Compamy Ltd | Vietnam |
| 185.132.43.9 | 3 | IONOS SE | United Kingdom |
| 95.173.161.147 | 3 | Netinternet Bilisim Teknolojileri AS | Türkiye |
| 212.47.66.218 | 2 | Contabo GmbH | France |
| 87.192.253.110 | 2 | Uzbektelekom Joint Stock Company | Uzbekistan |
| 103.46.186.148 | 2 | PT Air Lintas Komunikasi | Indonesia |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS197556 | Kar-Tel LLC | 6 | 1 |
| AS51167 | Contabo GmbH | 6 | 5 |
| AS31898 | Oracle Corporation | 4 | 1 |
| AS8560 | IONOS SE | 4 | 2 |
| AS24940 | Hetzner Online GmbH | 3 | 2 |
| AS51559 | Netinternet Bilisim Teknolojileri AS | 3 | 1 |
Captured requests
- /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh
HTTP client fingerprints (JA4H)
- po11nn0700_765287bee650
- po11nn0700_c5a94e7539c9
- po11nn0700_5a5182d16ecb
- po11nn0700_fd0bf528810b
CVE report
CVE report
Open a specific CVE from the CVE tracker.