A vulnerability in Apache APISIX versions 1.2 through 1.5 allows an attacker to access APISIX management data via the Admin API if the user has enabled the Admin API and removed the default IP restriction rules. In this configuration, the default access token can be used to interact with the management interface, potentially exposing sensitive configuration and control functions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting Apache APISIX's admin API. The exploit leverages the default API token (edd1c9f034335f136f87ad84b625c8f1) to authenticate and interact with the admin API, exploiting two CVEs (CVE-2020-13945 and CVE-2022-24112). The module can bypass IP restrictions using the batch-requests plugin and achieves remote code execution by injecting Lua code via the 'script' or 'filter_func' parameters in route definitions. The default payload is a Unix reverse shell, but any Metasploit-compatible payload can be used. The module is operational and weaponized, providing reliable RCE against vulnerable APISIX deployments. The main endpoints targeted are '/apisix/admin/routes' and '/apisix/batch-requests'. The code is well-structured, with clear separation of checking, exploitation, and cleanup logic, and is intended for use within the Metasploit framework.
This repository is a Go-based exploit tool targeting two vulnerabilities in Apache APISIX: CVE-2021-45232 (unauthenticated admin API access) and CVE-2020-13945 (default API key usage). The tool supports both single and batch target modes, reading targets from a file or command-line argument. The main logic is in the DataHandle package, with functions to check for unauthenticated access and default key vulnerabilities. For CVE-2021-45232, the tool attempts to export and import configuration via the admin API, injecting a Lua script that allows remote OS command execution. For CVE-2020-13945, it uses the default API key to create a malicious route with a Lua script, then triggers it to achieve code execution. The exploit is operational, providing a working getshell if the target is vulnerable. The endpoints targeted are the APISIX admin API paths, and the payload is a Lua script injected via HTTP requests. The repository is structured with Go source files under DataHandle, a main.go entry point, and a README with usage instructions.
This repository provides a proof-of-concept exploit for CVE-2020-13945, a remote code execution vulnerability in Apache APISIX versions 1.2 to 1.5. The exploit is implemented in a single Python script (CVE-2020-13945.py) and leverages the Admin API to plant a malicious Lua route that enables arbitrary OS command execution via HTTP requests. The script can be used to scan multiple targets or exploit a single target, and it supports triggering a reverse shell to the attacker's machine. The exploit requires the target APISIX instance to have the Admin API enabled, the access IP restriction rules deleted, and the default API key/token unchanged. The repository also includes a README.md with detailed usage instructions and a requirements.txt listing Python dependencies. The main attack vector is network-based, targeting the APISIX Admin API endpoint. Key fingerprintable endpoints include '/apisix/admin/routes' for planting the backdoor and '/check?cmd=' for executing commands. The exploit is a functional PoC and does not belong to any exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.