CVE-2025-0282: Ivanti Connect Secure - Stack-based Buffer Overflow
HoneyLabs honeypots recorded 130 probes matching CVE-2025-0282 from 15 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /dana/home/index.cgi
- /dana-na/auth/url_6/welcome.cgi
- /dana-na/auth/url_default/welcome.cgi
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 102.220.160.201 | 66 | VPS Dedicated LLC | Slovenia |
| 102.220.160.200 | 51 | VPS Dedicated LLC | Slovenia |
| 45.56.72.142 | 1 | Akamai Connected Cloud | United States |
| 138.197.221.54 | 1 | DigitalOcean, LLC | United States |
| 192.241.136.162 | 1 | DigitalOcean, LLC | United States |
| 185.3.95.77 | 1 | Akamai Connected Cloud | United Kingdom |
| 137.184.76.52 | 1 | DigitalOcean, LLC | United States |
| 143.244.148.132 | 1 | DigitalOcean, LLC | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS197769 | VPS Dedicated LLC | 117 | 2 |
| AS14061 | DigitalOcean, LLC | 8 | 8 |
| AS63949 | Akamai Connected Cloud | 5 | 5 |
Captured requests
- /dana-na/auth/url_default/welcome.cgi
HTTP client fingerprints (JA4H)
- ge11nn0400_9c3956fad5da
- ge11nn0300_dedeb29cc523
CVE report
CVE report
Open a specific CVE from the CVE tracker.