Eyesofnetwork operates a monitoring and network-management platform with a narrow product footprint centered on its core web-facing interface, which serves as the administrative and operational hub for the system. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, concentrated in the web interface through a durable pattern of input-handling and command-injection flaws including SQL injection, cross-site scripting, OS command injection, and sensitive-information exposure. The attack surface is characterized by the direct accessibility of the web interface and the administrative privileges typically granted to it, making these weakness classes particularly high-risk in network environments. Defenders should treat Eyesofnetwork disclosures as requiring prompt inventory and patching of exposed instances, especially those reachable from untrusted networks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eyesofnetwork over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8657CRITICAL An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all | Feb 6, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-8655HIGH An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to run arbitrary commands as root | Feb 7, 2020 | 7.8 | 94 | YES | YES |
CVE-2020-8656CRITICAL An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentic | Feb 7, 2020 | 9.8 | 92 | NO | YES |
CVE-2020-8654HIGH An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the /module | Feb 7, 2020 | 8.8 | 91 | NO | YES |
CVE-2020-9465CRITICAL An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform | Feb 28, 2020 | 9.8 | 83 | NO | YES |
CVE-2021-27513HIGH The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside." | Feb 22, 2021 | 8.8 | 41 | NO | NO |
CVE-2017-6088HIGH Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) displa | Apr 11, 2017 | 7.2 | 37 | NO | YES |
CVE-2022-41570CRITICAL An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur. | Sep 27, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-40643CRITICAL EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" confi | Jun 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-1000060CRITICAL EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root | Jul 17, 2017 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eyesofnetwork.
Media articles that mention a CVE ID that affects a product developed by Eyesofnetwork — matched by CVE ID, not by vendor name.