CVE-2017-9841General(oracle / communications_diameter_signaling_router)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch oracle communications_diameter_signaling_router systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-15. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • communications_diameter_signaling_router
  • phpunit

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-04-08); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Products
communications_diameter_signaling_routerphpunit

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-02-10: 1Mentions · 2026-02-22: 1Mentions · 2026-04-08: 2Mentions · 2026-07-08: 1Mentions · 2026-09-18: 1Mentions · 2026-10-02: 1Mentions · 2026-10-05: 1PoC Mentioned / Linked · 2026-02-10: 1Exploit Tool / Code · 2026-02-22: 1Active Exploitation · 2026-02-22: 1Active Exploitation · 2026-04-08: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-22: 1Technical Details · 2026-04-08: 202-1002-2204-0807-0809-1810-0210-05
Signal classification3 categories
General
350.0%
Active Exploitation
233.3%
Disclosure
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-221
Active Exploitation1
2026-04-082
Active Exploitation1General1
2026-07-081
General1
2026-09-181
General1
Full discourse8 posts
  • Root Rat@root_rat
    General

    🔀 Investigar la IP 185.250.37.153 (Contabo GmbH, Francia) bloqueada por CrowdSec en s1. Quiero un informe completo: quién es, qué ASN, reputación, historial de abuso, geolocalización precisa, puertos escaneados, vectores de ataque (ThinkPHP CVE-2018-20062, PHPUnit CVE-2017-9841, HTTP probing), y si es un actor conocido o probable bot. ⚡ Investigar IP 185.250.37.153 - reputación, historial de abuso, geolocalización, ASN Contabo, amenazas conocidas, ThinkPHP CVE-2018-20062, PHPUnit CVE-2017-9841 💻 ssh s1 "cd /opt/rattalks && echo '=== CROWDSEC ALERTS DETAIL ===' && docker compose exec -T crowdsec cscli alerts list --limit 50 2>&1 | grep '185.250.37.153' && echo && echo '=== TRAEFIK LOGS from this IP ===' && docker compose logs --since 24h traefik 2>&1 | grep '185.250.37.153' | tail -30 && echo && echo '=== BACKEND LOGS from this IP ===' && docker compose logs --since 24h backend 2>&1 | grep '185.250.37.153' | tail -20" 🔍 Investigación: IP 185.250.37.153 (Contabo GmbH) 📋 Datos generales CampoValorIP185.250.37.153ASNAS51167 — Contabo GmbHPaís registro🇫🇷 FR (datacenter Contabo, probablemente Núremberg/Múnich DE)TipoVPS / Dedicated hosting de bajo costoReputación⚠️ Alta probabilidad en listas negras 🕵️ Patrón de ataque detectado Esta IP ya atacó ayer y volvió hoy — misma secuencia las dos veces: Timestamp (UTC)Alertas CrowdSec2026-04-07 12:52:03http-probing + CVE-2017-9841 + thinkphp-cve-2018-200622026-04-08 07:51:28http-probing + CVE-2017-9841 + thinkphp-cve-2018-20062 3 escenarios en cada visita, siempre en el mismo orden: HTTP Probing — reconoce la superficie del servidor PHPUnit CVE-2017-9841 — intenta explotar /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php (RCE, CVSS 9.8) ThinkPHP CVE-2018-20062 — intenta RCE vía parámetro filter en thinkphp/library/think/App.php Es un escaneo automatizado (bot/herramienta de pentest masivo). El patrón secuencial es típico de tools como nuclei, nikto o frameworks similares que lanzan payloads de CVEs conocidos en cadena. 🎯 ¿Nos afecta? No. RatTalks no usa ni ThinkPHP ni PHPUnit expuesto, así que los payloads no habrían ejecutado nada. Además: ✅ CrowdSec baneó la IP en ambas ocasiones antes de que pudiera seguir ✅ Los logs de Traefik no muestran tráfico de esta IP llegando al backend → el ban funciona correctamente ✅ Los logs del backend no registran nada de esta IP → nunca pasó el proxy 🏢 Sobre Contabo Contabo es un proveedor alemán de VPS baratos. Es notoriamente popular entre actores de amenazas porque: Precios muy bajos → easy spin-up de instancias de ataque Registro con mínima verificación Amplio historial de abuso reportado ✅ Acciones recomendadas Mantener el ban de CrowdSec — ya en vigor, expira en ~20h. Opcionalmente se puede hacer permanente No es necesario un ban permanente — es bot genérico, no un actor dirigido contra nosotros Todo OK — la infraestructura está parcheada y el stack de seguridad funciona como debe ¿Quieres que convierta el ban en permanente, o lo dejamos con las reglas automáticas de CrowdSec?

    Post summary

    The post documents an automated exploit attempt against ThinkPHP and PHPUnit vulnerabilities that was blocked before reaching the target, confirms the system is patched, and contains no evidence of actual exploitation or new vulnerability disclosure.

    41029104.0K
    17.3K followersView on X
  • Miguel Chacón@michaca94
    General

    🛡️ Mis honeypots en 7 días: 499.519 eventos desde 6.018 IPs (▲49 %). Un ataque cada 1,2 s. Una IP de 🇺🇸 Estados Unidos pasó por 7 sensores de 5 países en 23,7 horas. Lo más atacado: Telnet, SMB y MySQL. CVE más buscado: CVE-2017-9841. #ciberseguridad #honeypot #CTI

    Post summary

    The tweet reports a high volume of honeypot events and notes that CVE-2017-9841 is the most searched CVE, but offers no PoC, exploit, patch, or technical details about it.

    10010123
    191 followersView on X
  • sicehice@sicehice
    General

    #RCE attempt targeting PHPUnit (CVE-2017-9841) #RondoDox #Mirai 2026-07-07 23:40:29 UTC Source IP: 94.154.43.64 🇹🇷 IOCs: hxxp://45.153.34.153/rondo.dtm.sh 45.153.34.153 🇳🇱 79450efb960885c2f6910f96f75d9959 rondo2012@atomicmail.io https://t.co/crY8vKZY1i

    Post summary

    The post reports a suspected RCE attempt targeting PHPUnit via CVE‑2017‑9841 but provides no PoC, exploit code, or mitigation details.

    01001340
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting PHPUnit (CVE-2017-9841) #rondodox 2026-04-04 21:37:20 UTC Source IP: 124.198.131.185 🇺🇸 IOCs: hxxp://45.92.1.50/rondo.dtm.sh 45.92.1.50 🇳🇱 rondo2012@atomicmail.io https://t.co/FElKNzgX6U

    Post summary

    An active remote code execution attempt against PHPUnit CVE‑2017‑9841 has been reported, with associated IOCs (IP, domain, email) but without any disclosed patch or exploit tool details.

    01010294
    1.7K followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #MediumCompleteness To Cache A Predator: ILOVEPOOP Toolkit Discovery, Global Traffic & Honeypot Observations Exploiting React2Shell (CVE-2025-55182) | 06-02-2026 Source: https://main.whoisxmlapi.com/blog/to-cache-a-predator-ilovepoop-toolkit-react2shell-cve-2025-55182 Key details below ↓ 💀Threats: Ilovepoop_tool, React2shell_vuln, Mirai, Kimwolf, 🎯Victims: Organizations using next.js or react server components, Industrial control systems 🏭Industry: Ics, Iot, E-commerce, Education, Media, Energy, Entertainment, Financial, Retail, Government, Telco, Healthcare 🌐Geo: Brazil, Poland, India, Asia, Bulgarian, Vietnam, Netherland, Singapore, Egypt, Hong kong, Russia, Canada, Serbia, China, Australia, Bulgaria, Philippines, Malaysia, Taiwan, United kingdom, Japan, Laos, Netherlands, Latin america, Mexico, Germany, Korea, France 🔓CVEs: CVE-2025-55182 \[[Vulners](https://vulners.com/cve/CVE-2025-55182)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - facebook react (19.0.0, 19.1.0, 19.1.1, 19.2.0) CVE-2017-9841 \[[Vulners](https://vulners.com/cve/CVE-2017-9841)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - phpunit_project phpunit (le4.8.27, <5.6.3) CVE-2023-1389 \[[Vulners](https://vulners.com/cve/CVE-2023-1389)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - tp-link archer_ax21_firmware (<1.1.4) 🤖LLM extracted TTPs:` T1021, T1046, T1078, T1110, T1133, T1190, T1211, T1590, T1592.004, T1595, ... 🧨IOCs: - File: 5 - IP: 30 💽Software: Firefox, Linux, PHPUnit, Android 🔢Algorithms: deflate, gzip, exhibit 📜Programming Languages: php, javascript 💻Platforms: apple, intel #threatreport: The report on React2Shell (CVE-2025-55182) reveals a coordinated exploitation campaign characterized by the use of the ILOVEPOOP toolkit, observed through global telemetry and honeypot data. Following the public disclosure of the vulnerability in December 2025, exploit attempts were recorded by Niihama sensors within just 20 hours, highlighting the promptness of hostile actors in leveraging this security flaw. Key findings indicate a high centralization of attacker infrastructure around two nodes hosted in the Netherlands, which accounted for a significant portion of the exploit traffic. The ILOVEPOOP toolkit, identified as a single-operator solution, was active across nine nodes and generated a total of 672 exploit attempts with uniform exploit headers and specific patterns signaling the React2Shell methodology. For instance, requests from the toolkit consistently featured multipart data types and peculiar headers like "Next-Action: x" and user-agent strings that suggest a coordinated effort to exploit various Next.js components. Extended scanning activities were noted from January 5th to February 6th, 2026, with a total of 894 requests originating from 43 unique IP addresses. This persistent probing was directed at specific Next.js routes, including bulk scanning of JavaScript bundles for sensitive information like credentials and API keys. The outreach was diverse, targeting thousands of organizations across several regions, particularly in the U.S., with substantial traffic aiming for Next.js vulnerabilities. One noteworthy aspect of the campaign was a cross-protocol attack where a React2Shell exploit attempt was sent to a POP3 daemon, showcasing a multi-protocol delivery mechanism that could evade standard security measures. This manipulation involved leveraging prototype pollution to achieve remote code execution via the React Server Components framework. Such behavior underscores the evolving strategies of threat actors to exploit multiple protocols simultaneously, indicating a potentially advanced and adaptable threat landscape. Two specific IP addresses from the attack infrastructure, 87.121.84.24 and 193.142.147.209, exhibited different behaviors; the former was confirmed to actively exploit React2Shell while the latter showed a mix of probing consistent with IoT botnet activity. The campaign's high signal of scanning activity indicates not only immediate exploitative actions but also a broader reconnaissance for potential vulnerabilities across various services and infrastructures. The data underscores a need for heightened awareness and preemptive security measures against the React2Shell threat and similar toolkit behaviors, particularly for organizations using Next.js and involved in web application development. The evolving nature of the attack patterns necessitates continuous monitoring and adaptation of cybersecurity defenses, especially in light of the emerging multi-protocol exploitation strategies evidenced in this campaign.

    Post summary

    The report documents an active exploitation campaign against React2Shell (CVE‑2025‑55182) using the ILOVEPOOP toolkit, with rapid post‑disclosure attacks, multi‑protocol delivery, and extensive reconnaissance, underscoring the need for heightened vigilance.

    00020183
    587 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2017-9841 - critical 🚨 PHPUnit - Remote Code Execution &gt; PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitra... 👾 https://cloud.projectdiscovery.io/library/CVE-2017-9841 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the critical CVE‑2017‑9841 vulnerability in PHPUnit, detailing that versions prior to 4.8.28 and 5.x before 5.6.3 allow remote code execution, and links to a library page with further information. No exploit code, patch, or active exploitation is mentioned.

    01001188
    890 followersView on X
  • Huntback.io@Huntbackio

    Their job against us isn't map scraping. It's commodity mass-exploitation: • PHPUnit CVE-2017-9841 (64) • F5 BIG-IP CVE-2023-46747 • Apache CVE-2021-42013 • NetScaler SAML, PHP-CGI UAs: spoofed iPhone + Mac Chrome, libredtail-http. Nothing announces itself honestly.

    1000024
    42 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: High CVE: CVE-2017-9841 Product: PHPUnit / PHPUnit Summary: VulnCheck reports real-world exploitation activity affecting PHPUnit / PHPUnit. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 22 Nov 2020 Source: https://vulncheck.com/xdb/2f94822ef64a #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #PHPUnit #CVE_2017_9841 #ActiveExploitation #Exploit

    0000066
    226 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclecommunications_diameter_signaling_router---
Appphpunit_projectphpunit---

Explore more