CVE-2019-0708General(huawei / agile_controller-campus)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch huawei agile_controller-campus systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

8.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agile_controller-campus
  • agile_controller-campus_firmware
  • aptio
  • aptio_firmware

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 13 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 7 classified signals
  • Disclosure: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-07-08); latest day: 1
  • 14 total mentions across 13 days

Affected systems

Products
agile_controller-campusagile_controller-campus_firmwareaptioaptio_firmwareatellica_solutionatellica_solution_firmwareaxiom_multix_maxiom_multix_m_firmwareaxiom_vertix_md_traumaaxiom_vertix_md_trauma_firmware

18 versions affected across 131 products

Deep dive

Activity timeline14 mentions / 13d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-23: 1Mentions · 2026-03-12: 1Mentions · 2026-03-25: 1Mentions · 2026-05-15: 1Mentions · 2026-05-23: 1Mentions · 2026-07-08: 2Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1Mentions · 2026-09-16: 1Mentions · 2026-09-18: 1Mentions · 2026-09-21: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-07-08: 1Exploit Tool / Code · 2026-07-08: 1Exploit Tool / Code · 2026-09-16: 1Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-18: 1Active Exploitation · 2026-09-21: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-07-08: 2Technical Details · 2026-02-23: 1Technical Details · 2026-05-23: 1Technical Details · 2026-07-08: 2Technical Details · 2026-09-16: 102-1102-2303-1203-2505-1505-2307-0809-1309-1409-1609-1809-2109-22
Signal classification4 categories
General
750.0%
Active Exploitation
428.6%
Disclosure
214.3%
Patch
17.1%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-111
Active Exploitation1
2026-02-231
General1
2026-03-121
General1
2026-03-251
General1
2026-05-151
General1
2026-05-231
Disclosure1
2026-07-082
Disclosure1Patch1
2026-09-131
General1
2026-09-141
General1
2026-09-161
Active Exploitation1
2026-09-181
Active Exploitation1
2026-09-211
Active Exploitation1
2026-09-221
General1
Full discourse14 posts
  • Nitin Gavhane@NitinGavhane_
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab. #BugBounty #CVE #CyberSecurity #SecurityResearch #EthicalHacking #InfoSec #AppSec #Pentesting

    Post summary

    The text is an educational timeline listing historically significant CVEs for bug bounty context, offering general learning advice without disclosing new vulnerabilities, sharing PoCs, exploits, patches, or reporting active exploitation.

    31411016411.3K
    3.5K followersView on X
  • OS Dev@OSdev_
    Disclosure

    BlueKeep (CVE-2019-0708) wasn't scary because it was "just another RCE." It was scary because it was wormable. The vulnerability existed in Windows Remote Desktop Services (RDP) and could be triggered before authentication, with no user interaction. An attacker only needed to send specially crafted RDP packets to a machine with RDP exposed. Once exploited, arbitrary code could run on the target system. What made BlueKeep unique was where the bug occurred. During the RDP connection sequence, virtual channels are created before security begins. The vulnerability involved the internal "MS_T120" static virtual channel, which could be improperly bound during the GCC Conference Initialization phase. Because this happens before authentication, a compromised machine could automatically scan for other vulnerable systems and spread without user interaction similar to how WannaCry propagated. The exploit itself wasn't trivial, but the design made defenders nervous enough that Microsoft released patches for unsupported operating systems like Windows XP, something it rarely does. BlueKeep remains one of the best case studies for understanding RDP internals, virtual channels, pre-authentication attack surfaces, and why protocol design matters just as much as implementation security.

    Post summary

    The post outlines BlueKeep as a pre‑authentication RCE with wormable characteristics, details its technical exploitation vector via virtual channels, and notes that Microsoft issued patches for unsupported systems.

    111095475.2K
    5.0K followersView on X
  • TI Mindmap HUB@ti_mindmap_hub
    Active Exploitation

    🟡 BlueKeep (CVE-2019-0708) is still being actively exploited. Seven years old. Oldest CVE we've flagged as under active exploitation in this series. Patch coverage, not patch age, is the actual variable.

    Post summary

    The tweet asserts that CVE-2019-0708 (BlueKeep) remains under active exploitation seven years post-disclosure, highlighting patch coverage as the critical mitigation factor.

    1101024
    19 followersView on X
  • OS Dev@OSdev_
    Patch

    https://www.trellix.com/blogs/research/rdp-stands-for-really-do-patch-understanding-the-wormable-rdp-vulnerability-cve-2019-0708/

    Post summary

    The blog outlines BlueKeep (CVE‑2019‑0708), providing technical details, a PoC and exploit reference, and emphasizes Microsoft’s patch, while noting that active exploitation had not been observed.

    00021441
    5.0K followersView on X
  • Matt Van Bibber@mattvanbibber
    General

    @pjcolbeck RDP.... CVE-2019-0708 CVE-2019-1181 CVE-2019-1182 CVE-2024-43533 CVE-2024-43582 CVE-2024-49115 CVE-2024-49128 CVE-2025-24035 CVE-2025-24045 CVE-2025-26645 CVE-2025-27480 CVE-2025-29966 CVE-2025-29967 CVE-2025-48817 CVE-2025-50171 CVE-2025-53722 CVE-2025-55340

    Post summary

    The tweet merely lists a series of CVE identifiers without providing additional context or evidence.

    00020180
    1.4K followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The post lists Windows CVE identifiers without providing details, patches, or exploitation information, placing it in the General category.

    10000106
    15 followersView on X
  • Grok@grok
    General

    Windows 7 n'est plus supporté depuis janvier 2020, donc pas de mises à jour de sécurité. Sur un LAN, les risques incluent : - Vulnérabilités non corrigées (ex. BlueKeep CVE-2019-0708 : exécution de code distant). - Propagation de malwares entre appareils connectés. - Exposition à des exploits si un appareil est infecté (via USB ou autre). Si le LAN est isolé d'internet, les risques diminuent, mais persistent via menaces internes. Passez à une version récente pour plus de sécurité.

    Post summary

    The post warns about the risks of running unpatched Windows 7 on a LAN, citing BlueKeep (CVE‑2019‑0708) as an example of remote code execution, but it does not provide any PoC, exploit code, or patch details.

    1000039
    8.1M followersView on X
  • OTbase@langnergroup
    General

    Last patch on this XP box: 2013. 181 security patches. BlueKeep is still sitting on it. https://otbase.com OTbase shows last-patch date and CVE-2019-0708 on that exact station. #OTSecurity #ICS #OTbase https://t.co/04DxCZfvdH

    Post summary

    The tweet highlights an unpatched XP workstation hosting CVE-2019-0708 (BlueKeep) since 2013 via the OTbase asset tool, but provides no exploit, PoC, active attack, or remediation details.

    00000131
    3.9K followersView on X
  • BT Haberler@BTHaberler
    Active Exploitation

    Kaspersky, Rus İşletmelerini Hedef Alan Üç Ayrı Siber Casusluk Grubunu Ortaya Çıkardı! Kaspersky, Rus kuruluşlarına karşı eş zamanlı faaliyet gösteren üç farklı tehdit grubunu tespit etti: "NightEagle" grubu, GhostContainer adlı modüler arka kapı ve BlueKeep (CVE-2019-0708) açığıyla Microsoft Exchange sunucularına sızarken, "Hacking Cat" grubu Exchange açığı CVE-2021-26855 üzerinden Gorilla RAT ve Monkey fidye yazılımını dağıtıyor, "Toy Ghouls" grubu ise MQTT ve Element Messenger üzerinden komuta kontrol kuran "Bird Agent" arka kapısını kullanıyor. • NightEagle'ın VPN bağlantılarının Rus ağ segmentindeki IP adreslerinden geldiği, ayrıca DCSync saldırılarıyla yetki yükseltmesi yaptığı tespit edildi. • Üç grubun da farklı araç ve teknikler kullanması, Rus kuruluşlarının aynı anda birden fazla bağımsız tehdit aktörünün hedefinde olduğunu gösteriyor. Üç farklı casusluk ve fidye yazılımı grubunun aynı ülkedeki kuruluşları eş zamanlı ama birbirinden bağımsız biçimde hedef alması, büyük ve stratejik önemi yüksek ekonomilerin sürekli olarak çok cepheli siber tehdit baskısı altında kaldığını gösteriyor. #SiberGüvenlik #APT #FidyeYazılımı

    Post summary

    The report details three Russian-linked threat groups exploiting BlueKeep (CVE-2019-0708) and Exchange (CVE-2021-26855) vulnerabilities to deploy backdoors and ransomware, indicating active exploitation in the wild.

    0000042
    44 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    NightEagle operators hit Exchange via CVE-2020-0688 to plant GhostContainer. They pull the http://ASP.NET machine keys, then overwrite VIEWSTATE so the server deserializes attacker-controlled data and executes payloads straight from memory. GhostWebShell plus Neo-reGeorg handle persistence while Microsoft dev tunnels and rdp2tcp move traffic laterally; CVE-2019-0708 and DCSync round out the chain. Hacking Cat started in Feb 2024 abusing CVE-2021-26855 to drop the Go-based Gorilla RAT. From there they push Monkey ransomware builds in Rust, .NET, C++, or Go. The Rust samples use ChaCha20-Poly1305; the .NET ones stick to AES-256-CBC. Artifacts first appeared late summer 2025. Toy Ghouls has run mqtt-bird-agent and matrix-bird-agent since mid-2026. Both register as Windows services, seed their keys from MachineGuid, and beacon over HiveMQ MQTT or Element Matrix after Evil-WinRM entry. Track the distinct TTP sets on the same Exchange hosts before you merge the incidents.

    Post summary

    The text reports active, ongoing exploitation of multiple Exchange CVEs (CVE-2020-0688, CVE-2021-26855, CVE-2019-0708) by distinct threat actors (NightEagle, Hacking Cat, Toy Ghouls) deploying custom toolchains for persistence and lateral movement.

    00000100
    172 followersView on X
  • chaos@konig0000
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab.

    Post summary

    The text is a high-level educational timeline of notable CVEs and years. It encourages learning root causes, patches, and safe lab reproduction but does not provide specific PoC, exploit, patch, technical, or active exploitation details.

    00000121
    19.8K followersView on X
  • PatchDay Alert@patchdayalert
    Disclosure

    CVE-2019-0708 scared Microsoft so badly they patched Windows XP. A wormable RDP bug with no auth required. This is the story behind BlueKeep and why your RDP shouldn't face the internet. https://patchdayalert.com/blog/bluekeep-cve-2019-0708-rdp-wormable/?utm_source=twitter&utm_medium=social&utm_campaign=auto-drip&utm_content=bluekeep-cve-2019-0708-rdp-wormable

    Post summary

    The text recounts the BlueKeep (CVE‑2019‑0708) vulnerability, highlighting Microsoft’s patch to Windows XP and noting that the wormable RDP flaw requires no authentication.

    0000042
    47 followersView on X
  • fichwgrk@grokfc755
    General

    @grok What is BlueKeep (CVE-2019-0708) and what does it affect? (respond in fun mode).

    Post summary

    The tweet simply asks for an explanation of BlueKeep (CVE-2019-0708) and its affected systems without providing any additional information.

    0000011
    5 followersView on X
  • seantelligence@niksadecimal
    Active Exploitation

    Nice little blast from the past seeing a server running wide open ports on Server 2008 in 2026, which just got pwned by BlueKeep (CVE-2019-0708). Really nice. Alright, team. https://t.co/awoseFu4vh

    Post summary

    The tweet reports that a 2026 Windows Server 2008 machine was compromised by BlueKeep (CVE‑2019‑0708) in the wild.

    0000096
    408 followersView on X
CPE platform detail139 entries

139 of 139 entries

PartVendorProductVersionTarget SWTarget HW
HWhuaweiagile_controller-campus---
OShuaweiagile_controller-campus_firmwarev100r002c00--
OShuaweiagile_controller-campus_firmwarev100r002c10--
HWhuaweibh620_v2---
OShuaweibh620_v2_firmwarev100r002c00--
HWhuaweibh621_v2---
OShuaweibh621_v2_firmwarev100r002c00--
HWhuaweibh622_v2---
OShuaweibh622_v2_firmwarev100r001c00--
HWhuaweibh640_v2---
OShuaweibh640_v2_firmwarev100r002c00--
HWhuaweich121---
OShuaweich121_firmwarev100r001c00--
HWhuaweich140---
OShuaweich140_firmwarev100r001c00--
HWhuaweich220---
OShuaweich220_firmwarev100r001c00--
HWhuaweich221---
OShuaweich221_firmwarev100r001c00--
HWhuaweich222---
OShuaweich222_firmwarev100r002c00--
HWhuaweich240---
OShuaweich240_firmwarev100r001c00--
HWhuaweich242---
OShuaweich242_firmwarev100r001c00--
HWhuaweich242_v3---
OShuaweich242_v3_firmwarev100r001c00--
HWhuaweie6000---
HWhuaweie6000_chassis---
OShuaweie6000_chassis_firmwarev100r001c00--
OShuaweie6000_firmwarev100r002c00--
HWhuaweielog---
OShuaweielog_firmwarev200r003c10--
HWhuaweiespace_ecs---
OShuaweiespace_ecs_firmwarev300r001c00--
HWhuaweigtsoftx3000---
OShuaweigtsoftx3000_firmwarev200r001c01spc100--
OShuaweigtsoftx3000_firmwarev200r002c00spc300--
OShuaweigtsoftx3000_firmwarev200r002c10spc100--
HWhuaweioceanstor_18500---
OShuaweioceanstor_18500_firmwarev100r001c30spc300--
HWhuaweioceanstor_18800---
OShuaweioceanstor_18800_firmwarev100r001c30spc300--
HWhuaweioceanstor_18800f---
OShuaweioceanstor_18800f_firmwarev100r001c30spc300--
HWhuaweioceanstor_hvs85t---
OShuaweioceanstor_hvs85t_firmwarev100r001c00--
OShuaweioceanstor_hvs85t_firmwarev100r001c30spc200--
HWhuaweioceanstor_hvs88t---
OShuaweioceanstor_hvs88t_firmwarev100r001c00--
OShuaweioceanstor_hvs88t_firmwarev100r001c30spc200--
HWhuaweirh1288_v2---
OShuaweirh1288_v2_firmwarev100r002c00--
HWhuaweirh1288a_v2---
OShuaweirh1288a_v2_firmwarev100r002c00--
HWhuaweirh2265_v2---
OShuaweirh2265_v2_firmwarev100r002c00--
HWhuaweirh2268_v2---
OShuaweirh2268_v2_firmwarev100r002c00--
HWhuaweirh2285_v2---
OShuaweirh2285_v2_firmwarev100r002c00--
HWhuaweirh2285h_v2---
OShuaweirh2285h_v2_firmwarev100r002c00--
HWhuaweirh2288_v2---
OShuaweirh2288_v2_firmwarev100r002c00--
HWhuaweirh2288a_v2---
OShuaweirh2288a_v2_firmwarev100r002c00--
HWhuaweirh2288e_v2---
OShuaweirh2288e_v2_firmwarev100r002c00--
HWhuaweirh2288h_v2---
OShuaweirh2288h_v2_firmwarev100r002c00--
HWhuaweirh2485_v2---
OShuaweirh2485_v2_firmwarev100r002c00--
HWhuaweirh5885_v2---
OShuaweirh5885_v2_firmwarev100r001c00--
HWhuaweirh5885_v3---
OShuaweirh5885_v3_firmwarev100r003c00--
HWhuaweiseco_vsm---
OShuaweiseco_vsm_firmwarev200r002c00--
HWhuaweismc2.0---
OShuaweismc2.0_firmwarev500r002c00--
OShuaweismc2.0_firmwarev600r006c00--
HWhuaweiuma---
OShuaweiuma_firmwarev200r001c00--
OShuaweiuma_firmwarev300r001c00--
HWhuaweix6000---
OShuaweix6000_firmwarev100r002c00--
HWhuaweix8000---
OShuaweix8000_firmwarev100r002c20--
OSmicrosoftwindows_7---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2--
HWsiemensaptio---
OSsiemensaptio_firmware---
HWsiemensatellica_solution---
OSsiemensatellica_solution_firmware---
HWsiemensaxiom_multix_m---
OSsiemensaxiom_multix_m_firmware---
HWsiemensaxiom_vertix_md_trauma---
OSsiemensaxiom_vertix_md_trauma_firmware---
HWsiemensaxiom_vertix_solitaire_m---
OSsiemensaxiom_vertix_solitaire_m_firmware---
HWsiemenscentralink---
OSsiemenscentralink_firmware---
HWsiemenslantis---
OSsiemenslantis_firmware---
HWsiemensmobilett_xp_digital---
OSsiemensmobilett_xp_digital_firmware---
HWsiemensmultix_pro---
HWsiemensmultix_pro_acss---
OSsiemensmultix_pro_acss_firmware---
HWsiemensmultix_pro_acss_p---
OSsiemensmultix_pro_acss_p_firmware---
OSsiemensmultix_pro_firmware---
HWsiemensmultix_pro_navy---
OSsiemensmultix_pro_navy_firmware---
HWsiemensmultix_pro_p---
OSsiemensmultix_pro_p_firmware---
HWsiemensmultix_swing---
OSsiemensmultix_swing_firmware---
HWsiemensmultix_top---
HWsiemensmultix_top_acss---
OSsiemensmultix_top_acss_firmware---
HWsiemensmultix_top_acss_p---
OSsiemensmultix_top_acss_p_firmware---
OSsiemensmultix_top_firmware---
HWsiemensmultix_top_p---
OSsiemensmultix_top_p_firmware---
HWsiemensrapidpoint_500---
OSsiemensrapidpoint_500_firmware---
HWsiemensstreamlab---
OSsiemensstreamlab_firmware---
Appsiemenssyngo_lab_process_manager---
HWsiemensvertix_solitaire---
OSsiemensvertix_solitaire_firmware---
HWsiemensviva_e---
OSsiemensviva_e_firmware---
HWsiemensviva_twin---
OSsiemensviva_twin_firmware---

Explore more