Internet scanning activity is targeting ESAFENET Content Data Guard (CDG) 3, a secure document management and data leakage prevention platform used largely in the Chinese market, by attempting logins with a publicly known default account instead of exploiting a newly disclosed flaw. Observed requests targeted the /CDGServer3/SystemConfig endpoint and used the default username secadmin with the vendor-default password Est@Spc820, indicating opportunistic attempts to gain administrative access through unchanged credentials.
The activity follows earlier attention on ESAFENET CDG security issues and adds to a history of reported weaknesses tied to the product, including SQL injection, cross-site scripting (XSS), and weak or default passwords. Researchers noted that scanning against CDG has surfaced before, particularly after public disclosure of an XSS issue, underscoring that even complex-looking passwords provide no protection when they are shipped as defaults and remain widely known.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
The references describe active scanning targeting ESAFENET CDG 3 by attempting authentication to /CDGServer3/SystemConfig using the default username secadmin and password Est@Spc820, rather than exploiting a new software flaw.
The references state that scanning activity against ESAFENET CDG increased after a cross-site scripting vulnerability became public. No specific disclosure date for the XSS issue is provided in the source content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.