CVE-2021-4473Disclosure(topsecgroup / tianxin_internet_behavior_management_system)

MEDIUMCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch topsecgroup tianxin_internet_behavior_management_system systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplying a crafted objClass parameter containing shell metacharacters and output redirection. Attackers can exploit this vulnerability to write malicious PHP files into the web root and achieve remote code execution with the privileges of the web server process. This vulnerability has been fixed in version NACFirmware_4.0.0.7_20210716.180815_topsec_0_basic.bin. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-06-01 (UTC).

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tianxin_internet_behavior_management_system

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
tianxin_internet_behavior_management_system

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-08: 1Mentions · 2026-04-11: 1Mentions · 2026-04-19: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-11: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-19: 104-0704-0804-1104-19
Signal classification3 categories
Disclosure
240.0%
Active Exploitation
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure1Patch1
2026-04-081
Active Exploitation1
2026-04-111
Active Exploitation1
2026-04-191
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2021-4473 Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execu… https://www.cve.org/CVERecord?id=CVE-2021-4473

    Post summary

    The text announces CVE‑2021‑4473, describing a command injection vulnerability in the Reporter component that can be exploited without authentication.

    00000172
    57.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2021-4473 Exploit in the wild confirmed for CVE-2021-4473 (CVSS 9.8). Tianxin Internet Behavior Management System contains a command injection vulnerability in ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The alert indicates that CVE‑2021‑4473, a high‑severity command injection vulnerability, is actively exploited in the wild. No patch details or PoC information are included in the text.

    0000050
    5.6K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Shadowserver warns of active exploitation of CVE-2021-4473 in Tianxin systems. This 9.3 CVSS flaw allows unauthenticated RCE. Patch your firmware immediately! #ActiveExploit #TianxinRCE #CVE #CyberSecurity #InfoSec #RCE #NetworkSecurity #Shadowserver https://securityonline.info/tianxin-internet-behavior-management-active-exploit-cve-2021-4473/ https://t.co/hO0kRN68J2

    Post summary

    Shadowserver reports that CVE-2021-4473 is actively exploited in Tianxin systems, citing a 9.3 CVSS score and unauthenticated RCE, and urges users to patch firmware promptly.

    00000409
    11.1K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2021-4473: CRITICAL] Tianxin Internet Behavior Management System had a command injection vulnerability, now fixed in version NACFirmware_4.0.0.7_20210716. Exploitation evidence found by Shadowserver Found...#cve,CVE-2021-4473,#cybersecurity https://cvefind.com/CVE-2021-4473

    Post summary

    The post highlights a critical command‑injection flaw in Tianxin Internet Behavior Management System, confirms it has been patched in firmware version 4.0.0.7_20210716, and notes that Shadowserver has found exploitation evidence in the wild.

    00000179
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2021-4473: Tianxin Internet Behavior Managem... Unauthenticated RCE via shell metacharacters in objClass param - perfect for dropping webshells on Chinese enterprise ne... https://zerodaysignal.com/vulnerability/CVE-2021-4473 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2021‑4473, noting an unauthenticated remote code execution flaw involving shell metacharacters in the objClass parameter, and provides a link to a zero‑day signal page for further details.

    0000046
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptopsecgrouptianxin_internet_behavior_management_system---

Explore more