Huntress researchers John Hammond and Caleb Stewart detail a critical authentication bypass vulnerability (CVE-2022-36537) in the ZK Java framework bundled with ConnectWise R1Soft Server Backup Manager. By chaining the auth bypass with a backdoored JDBC driver upload, attackers can achieve RCE as root on the backup server and then push arbitrary code — including Lockbit 3.0 ransomware — to all downstream registered endpoints. Over 5,000 exposed instances were found on Shodan, posing massive supply chain risk for MSPs and their SMB clients. A patch (SBM v6.16.4) was released and validated by Huntress. An update notes that by February 2023, threat actors were actively exploiting this vulnerability in the wild to deploy backdoors on hundreds of servers.

10m read timeFrom huntress.com
Post cover image
Table of contents
Initial DiscoveryHuntress ResearchPotential ImpactOur FindingsStronger TogetherIndicators of CompromiseComplete TimelineResources and References