Matrix
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 08:35
- Modified
- 21/12/2025 08:35
- Updated at
- 21/12/2025 08:35
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 17 attack patterns (mitre), 3 malware, 2 sectors, 2 countries, 7 indicators, 11 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
11 CVEs 17 MITREs 3 Malwares 12 Observables 1 APTPublished 27/11/2024 18:19 · Modified 27/11/2024 18:32
Attack patterns (MITRE) (17)
-
T1005 usesData from Local System
-
T1543 usesCreate or Modify System Process
-
T1036 usesMasquerading
-
T1046 usesNetwork Service Discovery
-
T1573 usesEncrypted Channel
-
T1078 usesValid Accounts
-
T1102 usesWeb Service
-
T1496 usesResource Hijacking
-
T1110 usesBrute Force
-
T1562.001 usesDisable or Modify Tools
-
T1498 usesNetwork Denial of Service
-
T1135 usesNetwork Share Discovery
-
T1190 usesExploit Public-Facing Application
-
SSH Hijacking usesT1563.001
-
T1554 usesCompromise Host Software Binary
-
T1210 usesExploitation of Remote Services
-
T1059.006 usesPython
Malware (3)
Sectors (2)
- Technology targets
- Telecommunications targets
Countries (2)
- China targets
- Japan targets
Indicators (7)
-
2e7682abe30d93afb3bd9dee0011c450c1d72d727151344b8b7360441571e007indicates -
sponsored-ate.gl.at.ply.ggindicates -
aee08f24f2e0be5af8b9a7947e845e8364be2f8b5ff874fbc3e7a4c81ecdad83indicates -
0ee827d23752c2afc1b07e5312986703f63e05b8c4f1902f5db07bb494e4d057indicates -
fa1b9e78b59cdb26d98da8b00fe701697a55ae9ea3bd11b00695cfbba2b67a7aindicates -
424058facc8f16fd578190a612bc3f9178f5e393d345c2330c39436abb4d1142indicates -
8dfe94a1b02d1330886ad4458b32db3da4b872f9c2116657840de499fee5438aindicates
Vulnerabilities (CVE) (11)
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10562, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 01/05/2015
- Modified
- 22/04/2026
A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and …
- Published
- 16/05/2022
- Modified
- 20/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code …
- Attack vector
- NETWORK
- Published
- 09/06/2022
- Modified
- 21/12/2025
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This …
- Published
- 19/12/2017
- Modified
- 13/05/2026
- Published
- 20/12/2025
- Modified
- 20/12/2025
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This …
- Published
- 03/11/2021
- Modified
- 21/12/2025
Dasan GPON Routers contain an authentication bypass vulnerability. When combined with CVE-2018-10561, exploitation can allow an attacker to perform remote code execution.
- Published
- 31/03/2022
- Modified
- 20/12/2025
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended …
- Attack vector
- Network
- Published
- 18/09/2024
- Modified
- 21/12/2025
Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user …
- Published
- 07/08/2023
- Modified
- 20/12/2025