CVE-2022-36537 is an information disclosure vulnerability in the AuUploader component of ZK Framework. Crafted HTTP POST requests permit internal request forwarding, exposing sensitive application resources or reaching otherwise inaccessible endpoints. Listed affected releases include 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, and 8.6.4.1. In ConnectWise R1Soft Server Backup Manager, attackers can use the flaw to bypass authentication and access administrative functionality. Chaining this access with the legitimate JDBC-driver upload feature enables arbitrary code execution as root. Remote code execution is an application-specific exploit chain, not a direct capability of the underlying ZK flaw alone.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a fully operational exploit for CVE-2022-36537, targeting the ZK Framework and products using it, such as ConnectWise Recover and R1Soft Server Backup Manager. The main exploit script (CVE-2022-36537.py) is written in Python and automates the process of exploiting an authentication bypass in the ZK framework. It allows an attacker to read arbitrary files from the server and to deploy a malicious JDBC driver (compiled from Driver.java) as a backdoor. The Java payload, when loaded by the target, executes arbitrary system commands: on Linux, it opens a reverse shell to 192.168.1.3:2022; on Windows, it launches the calculator as a demonstration. The exploit is operational and requires the attacker to supply a target URL and, optionally, a file to read or to deploy the backdoor. The repository includes all necessary code, a requirements.txt for dependencies, and a README with usage instructions and affected versions. The attack is performed over HTTP(S) endpoints exposed by the vulnerable server, specifically targeting /zkau/upload and /login.zul. The exploit demonstrates both file read and remote code execution capabilities, making it a significant threat to unpatched systems.
This repository provides a working exploit for CVE-2022-36537, targeting the ZK Framework and products using it, such as ConnectWise R1Soft Server Backup Manager. The main exploit script (CVE-2022-36537.py) is written in Python and automates the process of exploiting an authentication bypass in the ZK framework's /zkau/upload endpoint. The exploit allows an unauthenticated attacker to read arbitrary files from the server and, more critically, to upload a malicious JDBC driver (compiled from Driver.java) as a backdoor. The Java payload, when loaded by the target, executes a reverse shell to a hardcoded IP (192.168.1.3:2022) on Linux or launches calc.exe on Windows, demonstrating remote code execution. The repository includes all necessary code to build the payload, exploit the vulnerability, and provides clear instructions in the README. The exploit is operational and can be used to achieve RCE on vulnerable systems. The endpoints /zkau/upload and /login.zul are key to the attack, and the payload is customizable by modifying the Java code. The repository is well-structured, with clear separation between exploit logic (Python) and payload (Java). No evidence of fake or detection-only code was found.
This repository provides a working exploit for CVE-2022-36537, targeting the ZK Framework and products using it, such as ConnectWise R1Soft Server Backup Manager and ConnectWise Recover. The main exploit script (CVE-2022-36537.py) is written in Python and automates the process of exploiting an authentication bypass in the ZK framework. It allows an attacker to read arbitrary files from the server and to achieve remote code execution by uploading a malicious JDBC driver (compiled from Driver.java). The Java payload (Driver.java) is a backdoored MySQL JDBC driver that, when loaded by the target, executes a reverse shell to 192.168.1.3:2022 (Linux) or launches calc.exe (Windows). The exploit interacts with endpoints such as /zkau/upload and /login.zul to perform the attack. The repository also includes a requirements.txt for dependencies and a README.md with background and usage instructions. The exploit is operational, providing both file read and code execution capabilities, and is not just a proof of concept.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information disclosure flaw in ZK Framework's AuUploader component allows attackers to forward HTTP requests to internal URIs, exposing sensitive information and otherwise unreachable endpoints. In ConnectWise R1Soft Server Backup Manager, attackers use it to bypass authentication and upload malicious JDBC drivers, enabling remote code execution and persistent backdoor access. Compromised R1Soft servers can then issue commands to connected backup agents, enabling downstream ransomware deployment. Public proof-of-concept exploits have been available since December 2022, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on February 27, 2023. Fixed releases include ZK Framework 9.6.2 and security updates for earlier branches, R1Soft SBM 6.16.4, and ConnectWise Recover 2.9.9; ZK Framework workarounds are also available.
A ZK Framework vulnerability described in the article's IPS signature list as remote code execution and reportedly exploited by LockBit actors.
A ZK Java Framework vulnerability described as enabling authentication bypass and remote code execution in ConnectWise R1Soft Server Backup Manager and its connected backup agents. Attackers used it to install a backdoor, execute commands on downstream systems through privileged backup agents, and exfiltrate sensitive documents. Researchers identified 286 backdoored R1Soft servers on 9 January 2023; 128 remained backdoored as of 3 March 2023.
An authentication bypass and sensitive-file disclosure vulnerability in the ZK Java framework affects applications using unpatched versions, including ConnectWise R1Soft Server Backup Manager SE. Huntress chained the bypass with legitimate administrative features to obtain root-level remote code execution on the backup server and arbitrary execution on downstream managed endpoints. The updated article confirms exploitation in the wild to deploy backdoors, superseding the original article's statement that no exploitation had been observed. LockBit 3.0 deployment was demonstrated in a controlled proof of concept; the content does not report ransomware deployment in real-world attacks. Fixes include ZK 9.7.2, R1Soft SBM 6.16.4, and ConnectWise Recover 2.9.9.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.