26 April 2021

Hackers target corporate and government networks via flaws in Soliton FileZen file-sharing servers


Hackers target corporate and government networks via flaws in Soliton FileZen file-sharing servers

Malicious actors are targeting companies and government organizations using two vulnerabilities in the popular file-sharing server Soliton FileZen to steal sensitive data.

The two flaws in question are CVE-2020-5639 and CVE-2021-20655. The first bug is a path traversal issue that allows a remote attacker to conduct directory traversal attacks via a specially crafted HTTP request. The second flaw is an OS command injection issue that allows a remote user to execute arbitrary shell commands on the target system.

Both bugs have been used as part of a widespread hacking campaign, with the Japanese Prime Minister’s Cabinet Office being one of the targets. The breach occurred in January this year when hackers gained unauthorized access to the agency’s FileZen servers and stole confidential personal information for 231 people (name, affiliation, contact information, etc.)

Soliton addressed both flaws in FileZen solutions with the release of firmware versions V4.2.8 and V5.0.3. The company has advised its customers to change all admin account passwords and reset access-control lists.

Back to the list

Latest Posts

Cyber Security Week in Review: April 19, 2024

Cyber Security Week in Review: April 19, 2024

In brief: the LabHost PhaaS platform shut down, Russian military hackers attacked critical infrastructure in the US and Europe, and more.
19 April 2024
Ukrainian military personnel targeted via messaging apps and dating sites

Ukrainian military personnel targeted via messaging apps and dating sites

The threat actor employs a range of software in their malicious activities, including both commercial programs and  open-source tools.
18 April 2024
Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
18 April 2024