CISA warns of hackers exploiting ZK Java Framework RCE flaw

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added CVE-2022-36537 to its “Known Exploited Vulnerabilities Catalog” after threat actors began actively exploiting the remote code execution (RCE) flaw in attacks.

is a high-severity (CVSS v3.1: 7.5) flaw impacting the ZK Framework versions 9.6.1,,, and, enabling attackers to access sensitive information by sending a specially crafted POST request to the AuUploader component.

“ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context,” mentions .

The flaw was discovered last year by Markus Wulftange and addressed by ZK on May 05, 2022, with .

ZK is an open-source Ajax Web app framework written in Java, enabling web developers to create graphical user interfaces for web applications with minimal effort and programming knowledge.

The ZK framework is widely employed in projects of all types and sizes, so the flaw’s impact is widespread and far-reaching.

Notable examples of products using the ZK framework include ConnectWise Recover, version 2.9.7 and earlier, and ConnectWise R1SoftServer Backup Manager, version 6.16.3 and earlier.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses a significant risk to the federal enterprise” – .

CISA set the deadline to apply the available security updates to March 20, 2023, giving federal agencies roughly three weeks to respond to the security risk and take proper action to secure their networks.

Actively exploited

The addition of this vulnerability to CISA’s Known Exploited Vulnerabilities Catalog comes after NCC Group’s Fox-IT team  describing how the flaw was being actively exploited in attacks.

According to Fox-IT, during a recent incident response, it was discovered that an adversary exploited CVE-2022-36537 to gain initial access to ConnectWise R1Soft Server Backup Manager software.

The attackers then moved to control downstream systems connected via the R1Soft Backup Agent and deployed a malicious database driver with backdoor functionality, enabling them to execute commands on all systems connected to that R1Soft server.

Based on that incident, Fox-IT investigated further and found that worldwide exploitation attempts against R1Soft server software have been underway since November 2022, detecting at least 286 servers running this backdoor as of January 9, 2023.

However, the exploitation of the vulnerability is not unexpected, as multiple proof-of-concept (PoC)  were published  in December 2022.

Therefore, tools to perform attacks against unpatched R1Soft Server Backup Manager deployments are widely available, making it imperative that administrators update to the latest version.