Vulnerability Report - February 2025
Introduction
This vulnerability report has been generated using data aggregated on Vulnerability-Lookup, with contributions from the platform’s community.
It highlights the most frequently mentioned vulnerability for February 2025, based on sightings collected from various sources, including MISP, Exploit-DB, Bluesky, Mastodon, GitHub Gists, The Shadowserver Foundation, Nuclei, and more. For further details, please visit this page.
The final section focuses on exploitations observed through The Shadowserver Foundation’s honeypot network.
February at a glance
Sightings repartition per day
Repartition of all type of sightings per day for the month of January.
For more detailed information, check out the Vulnerability-Lookup dashboard:
https://vulnerability.circl.lu
Top 15 vulnerabilities of the month
The podium belongs to Ivanti, Fortinet, and Microsoft.
Evolution per week
Week 6
Ranking
Insights from contributors
Week 7
Ranking
Insights from contributors
- The M120N Advanced Industrial/In-Vehicle LTE Router
- HP Universal Print Driver Series (PCL 6 and PostScript) - Potential Security Vulnerabilities
- Fortinet - Authentication bypass in Node.js websocket module and CSF requests
Week 8
Ranking
Insights from contributors
- Out-of-Cycle Security Bulletin: Session Smart Router, Session Smart Conductor, WAN Assurance Router: API Authentication Bypass Vulnerability (CVE-2025-21589)
- Palantir’s External Artifacts service (versions 105.110.1 through 105.115.0)
- SonicWall Firewall Vulnerability Exploited After PoC Publication
- Potential privilege escalation in IDPKI
Week 9
Ranking
Insights from contributors
Continuous exploitation
The sightings used for this analysis were mainly collected through The Shadowserver Foundation’s honeypot network.
Black Basta’s Leaked Chat Logs
On February 11, 2025, a significant leak exposed BLACKBASTA’s internal Matrix chat logs.
A bundle on Vulnerability-Lookup is tracking the observations we’ve detected related to Black Basta’s leaked chat logs. You will find all the impacted products, such as Zimbra, Microsoft Exchange Server, JetBrains, and PAN-OS.
As you can see, there are plenty of sighting correlations from Shadowserver and from MISP, with continuous exploitations.
CVE-2017-11882 (Microsoft Office) was detected in MISP seven years ago (MISP/5a17d980-5438-4503-ba89-693b0a950b0c). Additionally, recent exploitations have been observed for other CVEs. Various Nuclei templates are available for this set of vulnerabilities.
You can read an interesting comment with more details: Update on SVR Cyber Operations and Vulnerability Exploitation.
CVE-2016-6277 - Netgear
Thank you
Thank you to all the contributors and our diverse sources!
If you want to contribute to the next report, you can create your account.