# ColdFusion flaw exploited for webshells in Japan

Published: 2024-04-17 · Severity: high · Sectors: government-national, technology, infrastructure
Canonical: https://vorant.io/reports/42f55977-ebfb-5fe2-8b19-3545b546f2d3/coldfusion-flaw-exploited-for-webshells-in-japan

> Attackers exploited Adobe ColdFusion vulnerability CVE-2023-29300 to plant webshells on at least 66 devices in Japan, risking ORB-style relay abuse.

IPA (Japan's Information-technology Promotion Agency) reports that network-perimeter appliances running Adobe ColdFusion have been compromised via CVE-2023-29300, a remote code execution flaw already listed in CISA's Known Exploited Vulnerabilities catalog. Multiple domestic organizations had webshells installed on affected ColdFusion instances, and Taiwanese security vendor TeamT5 reported on March 18, 2024 that at least 66 devices in Japan were compromised through this vulnerability.

IPA warns that such network-penetrating attacks often lead to compromised devices being repurposed as Operational Relay Boxes (ORBs) — used to relay C2 traffic or obscure attacker origin, potentially turning victim organizations into unwitting stepping stones for further attacks against third parties. The advisory draws a parallel to the Volt Typhoon campaign in the US and Europe, which similarly abused vulnerable network devices (including TP-Link routers) for ORB-style relay infrastructure targeting critical infrastructure.

IPA urges organizations running Adobe ColdFusion to urgently apply patches per Adobe's APSB23-40 advisory (which also covers two additional vulnerabilities) and to review connection logs for signs of compromise or ORB-style relay activity, even if patches have already been applied. Organizations detecting evidence of exploitation are encouraged to report to IPA's contact point.

## Mentioned in this report

- Vulnerabilities: CVE-2023-29300 (KEV)
- Threat actors: Volt Typhoon
- Malware: Webshell
- Campaigns: Volt Typhoon

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert_orb.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/42f55977-ebfb-5fe2-8b19-3545b546f2d3/coldfusion-flaw-exploited-for-webshells-in-japan.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
