• Sign in
  • Register

Lost your password?

A password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.

Close
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
Cyber Attack

Hackers Exploit Cisco’s Hidden Backdoor: Critical Smart Licensing Flaws Under Active Attack

ClickControl

Author

March 21, 2025

Published


# Hackers Target Cisco Smart Licensing Utility Backdoor Vulnerability

Threat actors have begun exploiting unpatched Cisco Smart Licensing Utility (CSLU) instances vulnerable to a recently disclosed backdoor admin account. The Windows-based CSLU application, which allows administrators to manage licenses on-premises without connecting to Cisco’s cloud services, contains two critical security flaws patched in September.

The primary vulnerability (CVE-2024-20439) involves an undocumented static admin credential that permits unauthenticated attackers to remotely access vulnerable systems with administrative privileges through the application’s API. Cisco simultaneously addressed a second critical flaw (CVE-2024-20440) that allows attackers to access sensitive log files containing API credentials via crafted HTTP requests.

Security researcher Nicholas Starke reverse-engineered the vulnerability approximately two weeks after Cisco’s patch release, publishing technical details including the decoded hardcoded password. This disclosure appears to have facilitated the current exploitation attempts.

Johannes Ullrich from SANS Technology Institute has confirmed that attackers are now chaining these two vulnerabilities to target internet-exposed CSLU instances. While the attackers’ ultimate objectives remain unclear, they are also attempting to exploit other vulnerabilities, including an information disclosure flaw affecting Guangzhou Yingke Electronic DVRs.

Despite ongoing exploitation, Cisco’s Product Security Incident Response Team maintains they have found no evidence of attacks leveraging these vulnerabilities. This isn’t Cisco’s first experience with backdoor accounts, as similar hardcoded credentials have previously been discovered in several company products including DNA Center, IOS XE, WAAS, and Emergency Responder software.

The vulnerabilities only affect systems running vulnerable CSLU releases and are exploitable only when the application is actively running, as it’s not designed to operate in the background by default.

Keywords: Cisco Smart Licensing Utility vulnerability, CVE-2024-20439, backdoor admin account, Cisco security flaws, hardcoded credentials exploit, network security vulnerability

Share This Article
Tags: backdoor admin account Cisco security flaws Cisco Smart Licensing Utility vulnerability CVE-2024-20439 hardcoded credentials exploit network security vulnerability
Previous Article Urgent Critical RCE Vulnerability in
Next Article EXPOSED GitHub Supply Chain Breach
Curve Line
logo_white
Quick Links
  • Cybersecurity News
  • Video Guides
  • Shop
Company
  • Home
  • About us
  • Contact
  • Careers
  • Privacy Policy

(C) Copyright 2023-2026 ClickControl IT MSP & Cybersecurity, All Rights Reserved.