a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; } HKCERT has received threat intelligence indicating that threat actors are attempting to target Internet-facing... Impact Remote Code Execution Security Restriction Bypass Denial of Service System / Technologies affected CVE-2018-11511 ASUSTOR ADM versions <= 3.1.0.RFQ3 CVE-2018-16167 LogonTracer versions <= 1.2.0 CVE-2018-17254 JCK Editor component for Joomla! version = 6.4.4 CVE-2020-25223 Sophos SG UTM versions <= v9.705 MR5 Sophos SG UTM versions <= v9.607 MR7 Sophos SG UTM versions <= v9.511 MR11 CVE-2020-26919 NETGEAR JGS516PE versions < 2.6.0.43 CVE-2020-35713 Belkin LINKSYS RE6500 versions < 1.0.012.001 CVE-2020-7796 Zimbra Collaboration Suite (ZCS) version < 8.8.15 Patch 7 CVE-2021-1498 Cisco HyperFlex HX versions < 4.0(2e) Cisco HyperFlex HX versions < 4.5(2a) CVE-2021-24139 Photo Gallery (10Web Photo Gallery) WordPress plugin, versions < 1.5.55 CVE-2021-31755 Tenda AC11 versions <= 02.03.01.104_CN CVE-2021-32305 WebSVN versions < 2.6.1 CVE-2021-36380 Sunhillo SureLine versions < 8.7.0.1.1 CVE-2022-26143 Mitel MiCollab versions < R9.4SP1 & MiVoice Business Express <= R8.1 Solutions Apply fixes issued by the vendor: CVE-2018-11511 ASUSTOR ADM versions > 3.1.0.RFQ3 CVE-2018-16167 LogonTracer versions > 1.2.0 CVE-2018-17254 JCK Editor component for Joomla! version > 6.4.4 CVE-2020-25223 Sophos SG UTM versions > v9.705 MR5 Sophos SG UTM versions > v9.607 MR7 Sophos SG UTM versions > v9.511 MR11 CVE-2020-26919 NETGEAR JGS516PE versions >= 2.6.0.43 CVE-2020-35713 Belkin LINKSYS RE6500 versions >= 1.0.012.001 CVE-2020-7796 Zimbra Collaboration Suite (ZCS) version >= 8.8.15 Patch 7 CVE-2021-1498 Cisco HyperFlex HX versions >= 4.0(2e) Cisco HyperFlex HX versions >= 4.5(2a) CVE-2021-24139 Photo Gallery (10Web Photo Gallery) WordPress plugin, versions >= 1.5.55 CVE-2021-31755 Tenda AC11 versions > 02.03.01.104_CN CVE-2021-32305 WebSVN versions >= 2.6.1 CVE-2021-36380 Sunhillo SureLine versions >= 8.7.0.1.1 CVE-2022-26143 Mitel MiCollab versions < R9.4SP1 & MiVoice Business Express > R8.1 Note: Organisations are advised to review their externally accessible systems, identify whether any affected products or vulnerable versions are in use, and apply the relevant security patches or mitigation measures.
Threat actors are actively targeting internet-facing systems in Hong Kong's education sector by exploiting multiple known CVEs across a wide range of products, including network devices, content management systems, and collaboration software. The vulnerabilities, such as CVE-2018-11511 (CVSS 9.8) affecting ASUSTOR ADM version 3.1.0 and CVE-2018-17254 (CVSS 9.8) affecting JCK Editor for Joomla! version 6.4.4, can lead to remote code execution, security restriction bypass, and denial of service. Organizations must review external systems, identify any affected products, and apply the specific vendor-released patches, such as upgrading ASUSTOR ADM beyond version 3.1.0.RFQ3 and JCK Editor to a version greater than 6.4.4.