DEVCORE researchers published offensive research describing a remote-code-execution chain affecting Pulse Secure SSL VPN appliances, using Twitter as a case study. The work highlighted how chained vulnerabilities in internet-facing VPN infrastructure can provide a path from unauthenticated access to execution on the appliance, placing internal networks and authentication systems at risk.
Researcher Orange Tsai also disclosed flaws in roughly 250,000 internet-exposed Taiwanese home modems, largely associated with Chunghwa Telecom. An ISP configuration exposed an unauthenticated management and debugging service on TCP port 3097; arbitrary file reading and an unauthenticated RCE path could enable modem compromise and access to subscriber home networks. The issues were tracked as CVE-2019-13411, CVE-2019-13412, CVE-2019-15064, CVE-2019-15065, and CVE-2019-15066, with firmware remediation reported before disclosure.

Map this exposure pattern across your cloud, code, and identities.
6 events from the most recent confirmed update back to the earliest known activity.
DEVCORE and TWCERT/CC confirmed that public disclosure of the modem vulnerability chain could proceed.
Chunghwa Telecom reported that some customers still required on-site technician updates, delaying public disclosure of the vulnerabilities.
Chunghwa Telecom stated that firmware updates for affected modem devices had been completed.
Chunghwa Telecom stated that it was investigating the reported issues and patching affected equipment.
DEVCORE reported vulnerabilities affecting Chunghwa Telecom GPON broadband modems, including the exposed TCP/3097 management service, to Chunghwa Telecom through TWCERT/CC.
DEVCORE published research describing an internet-exposed TCP/3097 modem-management service affecting an estimated 250,000 Taiwanese modems, primarily Chunghwa Telecom devices. The disclosed flaws, assigned CVE-2019-13411, CVE-2019-13412, CVE-2019-15064, CVE-2019-15065, and CVE-2019-15066, enabled arbitrary file reading and unauthenticated remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.