ET WEB_SPECIFIC_APPS Evertz SDVN Authentication Bypass + Command Injection Attempt M2 (CVE-2025-4009)
Query · suricata
flow:established,to_server; xbits:isset,ET.CVE-2025-4009.attempt, track ip_dst; http.method; content:"GET"; http.uri; content:"/v.1.5/php/features/feature-transfer-export.php?"; fast_pattern; startswith; content:"action|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.CVE-2025-4009.attempt