Information exposure vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, and Hitachi Device Manager that may allow session hijacking. Affected versions: Hitachi Ops Center API Configuration Manager 10.0.0-00 to before 11.0.5-00; Hitachi Configuration Manager 8.5.1-00 to before 11.0.5-00; Hitachi Device Manager 8.4.1-00 to before 8.6.5-00.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a small standalone Python exploit repository containing one primary executable script (exploit.py), a README, and a requirements file. The exploit targets FreePBX versions earlier than 16.0.26.0 and claims CVE-2025-57819, abusing a SQL injection condition in the web-accessible AJAX endpoint /admin/ajax.php. The script is not part of a larger exploitation framework. Repository structure and purpose: README.md explains the vulnerability, usage, and expected outcomes; exploit.py implements the attack flow; requirements.txt lists Python dependencies. The Python script uses requests with TLS verification disabled, accepts a target host plus attacker callback host/port, and constructs SQL injection strings appended to GET requests against host/admin/ajax.php. Main exploit capability: the script attempts remote code execution by injecting INSERT statements into the cron_jobs table. The first injected cron job writes a base64-decoded PHP webshell into /var/www/html/pbxshell.php. The script then polls the resulting URL for up to 120 seconds to confirm creation. The second injected cron job writes a PHP reverse shell wrapper into /var/www/html/auto_rev.php; that payload executes a bash reverse shell to the supplied LHOST:LPORT. The script also starts a local netcat listener to catch the callback. Notable observables and targets include the vulnerable endpoint /admin/ajax.php, dropped files /var/www/html/pbxshell.php and /var/www/html/auto_rev.php, the pbxshell.php web path, the cron_jobs database table, and the reverse-shell callback over TCP to the attacker-supplied host and port. Overall, this is an operational RCE exploit with hardcoded payload behavior rather than a detection-only script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.