Reading the observatory store…
Reading the observatory store…
First seen 22 Sep 2026, last seen 22 Sep 2026 20:58 UTC (7h ago). 1 observations on record. Location is an estimate derived from registration data — the source and confidence are stated below.
| Port | Service | Product | Technologies | TLS | State | Banner | Last seen |
|---|---|---|---|---|---|---|---|
| 8443 tcp / tcp | https-alt | Apache HTTP Server 2.4.65 |
| TLSv1.3certificate
| open | no banner captured | 22 Sep 2026 7h ago |
| Observed at | Source | Collector | Confidence | Changed | State | Content hash |
|---|---|---|---|---|---|---|
| 22 Sep 2026 20:58 UTC | fingerprint | fingerprint-1 | high | changed | {"services":{"8443/tcp":{"state":"open","product":"Apache HTTP Server","version":"2.4.65","cert_sha256":"4a238f216d40a4a94df1a442c7aa174db1f59bdff004621635e01c… | 7820c40e9cf1527b3008c4b3dc0ab0622941f47… |
| Detected at | Type | Field | Previous | Current | Significance | Confidence |
|---|---|---|---|---|---|---|
| 22 Sep 2026 20:58 UTC | NEW SERVICE | service:8443/tcp | — | Apache HTTP Server 2.4.65 / TLSv1.3 | low | unknown |
| 22 Sep 2026 20:58 UTC | NEW ASSET | — | — | asset with 1 observed open endpoint(s) | low | unknown |
4 matches on this asset, each one unverified. Treat these as leads for manual review, never as findings.
| Identifier | Severity | CVSS | Product / version | Status | Match confidence | Evidence | Detected |
|---|---|---|---|---|---|---|---|
CVE-2025-58098 Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Ap… | high | 8.3 | Apache HTTP Server 2.4.65 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.65\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
CVE-2025-66200 mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an u… | medium | 5.4 | Apache HTTP Server 2.4.65 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.65\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
CVE-2025-65082 Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables cal… | medium | 6.5 | Apache HTTP Server 2.4.65 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.65\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
CVE-2025-54090 A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. | medium | 6.3 | Apache HTTP Server 2.4.65 | potential exposure — unverified | medium | {"match_reason":"keyword match on \"Apache HTTP Server 2.4.65\"","note":"version-string match only; not a confirmed exp… | 22 Sep 2026 |
Only one state has been recorded. The current document is shown without a predecessor — no comparison is implied.
{
"id": "ceb06ecb52616bd54a1198f249a1dab88",
"type": "ipv4",
"value": "116.66.194.146",
"hostname": null,
"reverseDns": null,
"asn": {
"number": 4007,
"name": "SUBISU-CABLENET-AS-AP - Subisu Cablenet (Pvt) Ltd, Baluwatar, Kathmandu, Nepal"
},
"organization": {
"id": "c2b1f62bdc5a33a0c2f97cc3d4861dcd6",
"name": "SUBISU-CABLENET-AS-AP - Subisu Cablenet (Pvt) Ltd, Baluwatar, Kathmandu, Nepal"
},
"location": {
"country": "NP",
"city": "Kathmandu",
"province": "Bagmati Province",
"district": "",
"confidence": "low",
"source": "ip-api.com"
},
"scopeStatus": "in_scope",
"priority": "NORMAL",
"firstSeen": "2026-09-22T07:25:53.279Z",
"lastSeen": "2026-09-22T20:58:43.905Z",
"observationCount": 1,
"openServices": 1,
"serviceCount": 1,
"technologies": [
"apache-http-server"
],
"vulnerabilityMatches": [
{
"id": "cd3e56770503aecf4c5dfbd9b35656f04",
"cve": "CVE-2025-58098",
"severity": "high",
"cvssScore": 8.3,
"summary": "Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd=\"...\" directives.\n\nThis issue affects Apache HTTP Server before 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.66, which fixes the issue.",
"product": "Apache HTTP Server",
"version": "2.4.65",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.65\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.65\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T21:04:20.586Z",
"assetValue": "116.66.194.146",
"serviceId": "c7cb69a9902277c8be19e8057fdec9592",
"port": 8443,
"technologySlug": "apache-http-server"
},
{
"id": "c2c23a6873da123728b98a91a6d63f276",
"cve": "CVE-2025-66200",
"severity": "medium",
"cvssScore": 5.4,
"summary": "mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid.\n\nThis issue affects Apache HTTP Server: from 2.4.7 through 2.4.65.\n\nUsers are recommended to upgrade to version 2.4.66, which fixes the issue.",
"product": "Apache HTTP Server",
"version": "2.4.65",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.65\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.65\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T21:04:20.583Z",
"assetValue": "116.66.194.146",
"serviceId": "c7cb69a9902277c8be19e8057fdec9592",
"port": 8443,
"technologySlug": "apache-http-server"
},
{
"id": "c3f1bb07b0d3856bc9479e57efbe08265",
"cve": "CVE-2025-65082",
"severity": "medium",
"cvssScore": 6.5,
"summary": "Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment variables set via the Apache configuration unexpectedly superseding variables calculated by the server for CGI programs.\n\nThis issue affects Apache HTTP Server from 2.4.0 through 2.4.65.\n\nUsers are recommended to upgrade to version 2.4.66 which fixes the issue.",
"product": "Apache HTTP Server",
"version": "2.4.65",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.65\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.65\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T21:04:20.581Z",
"assetValue": "116.66.194.146",
"serviceId": "c7cb69a9902277c8be19e8057fdec9592",
"port": 8443,
"technologySlug": "apache-http-server"
},
{
"id": "cbaa0cc104bddaedfbf7378c19b23d195",
"cve": "CVE-2025-54090",
"severity": "medium",
"cvssScore": 6.3,
"summary": "A bug in Apache HTTP Server 2.4.64 results in all \"RewriteCond expr ...\" tests evaluating as \"true\".\n\n\n\nUsers are recommended to upgrade to version 2.4.65, which fixes the issue.",
"product": "Apache HTTP Server",
"version": "2.4.65",
"status": "potential",
"matchConfidence": "medium",
"evidence": "{\"match_reason\":\"keyword match on \\\"Apache HTTP Server 2.4.65\\\"\",\"note\":\"version-string match only; not a confirmed exposure\",\"observed_product\":\"Apache HTTP Server\",\"observed_version\":\"2.4.65\",\"source\":\"nvd\"}",
"detectedAt": "2026-09-22T21:04:20.578Z",
"assetValue": "116.66.194.146",
"serviceId": "c7cb69a9902277c8be19e8057fdec9592",
"port": 8443,
"technologySlug": "apache-http-server"
}
],
"network": {
"id": "c0be2bbd289e1e80862945b5dbaf4fd38",
"prefix": "116.66.192.0/22",
"ipVersion": 4
},
"services": [
{
"id": "c7cb69a9902277c8be19e8057fdec9592",
"assetId": "ceb06ecb52616bd54a1198f249a1dab88",
"assetValue": null,
"port": 8443,
"protocol": "tcp",
"transport": "tcp",
"serviceType": "https-alt",
"product": "Apache HTTP Server",
"productVersion": "2.4.65",
"tlsVersion": "TLSv1.3",
"banner": null,
"state": "open",
"firstSeen": "2026-09-22T20:58:43.890Z",
"lastSeen": "2026-09-22T20:58:43.890Z",
"observationCount": 0,
"technologies": [
{
"slug": "apache-http-server",
"name": "Apache HTTP Server",
"category": "web-server",
"vendor": "Apache Software Foundation",
"version": "2.4.65",
"confidence": "high",
"evidence": "server: Apache/2.4.65 (Debian)",
"detectedAt": "2026-09-22T20:58:43.893Z"
}
],
"certificate": {
"id": "c023cecdec08a2b622ca5cf06ab2df7d1",
"sha256": "4a238f216d40a4a94df1a442c7aa174db1f59bdff004621635e01ce47083f3d5",
"subject": "CN=noc-nms,OU=ENGG,O=SUBISU,L=KTM,ST=Bagmati,C=NP",
"issuer": "CN=noc-nms,OU=ENGG,O=SUBISU,L=KTM,ST=Bagmati,C=NP",
"commonName": "noc-nms",
"notBefore": "2025-10-13T04:46:22.000Z",
"notAfter": "2125-09-19T04:46:22.000Z",
"sans": [],
"keyAlgo": "RSA",
"sigAlgo": "SHA256-RSA"
}
}
],
"certificates": [
{
"id": "c023cecdec08a2b622ca5cf06ab2df7d1",
"sha256": "4a238f216d40a4a94df1a442c7aa174db1f59bdff004621635e01ce47083f3d5",
"subject": "CN=noc-nms,OU=ENGG,O=SUBISU,L=KTM,ST=Bagmati,C=NP",
"issuer": "CN=noc-nms,OU=ENGG,O=SUBISU,L=KTM,ST=Bagmati,C=NP",
"commonName": "noc-nms",
"notBefore": "2025-10-13T04:46:22.000Z",
"notAfter": "2125-09-19T04:46:22.000Z",
"sans": [],
"keyAlgo": "RSA",
"sigAlgo": "SHA256-RSA"
}
],
"recentObservations": [
{
"id": "c878c4421a7bd9674c3af79460a0ce8f6",
"observedAt": "2026-09-22T20:58:43.898Z",
"source": "fingerprint",
"collector": "fingerprint-1",
"confidence": "high",
"state": {
"services": {
"8443/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.65",
"cert_sha256": "4a238f216d40a4a94df1a442c7aa174db1f59bdff004621635e01ce47083f3d5",
"tls_version": "TLSv1.3",
"service_type": "https-alt"
}
},
"technologies": [
"apache-http-server"
]
},
"evidence": {
"ports": [
21,
22,
23,
25,
53,
80,
110,
143,
443,
445,
465,
587,
993,
995,
1433,
1521,
3306,
3389,
5432,
5900,
6379,
8080,
8443,
8888,
9200,
27017
],
"services": 1,
"reachable": true,
"reverse_dns": "",
"ports_probed": 26,
"technologies": [
"apache-http-server"
],
"open_services": 1,
"probe_duration": 42893
},
"contentHash": "7820c40e9cf1527b3008c4b3dc0ab0622941f4704635c3b99d688dfeba44a47d",
"changed": true
}
],
"recentChanges": [
{
"id": "c46ced50cba143c99cc6d79dff3b1fcc0",
"changeType": "NEW_SERVICE",
"assetId": "ceb06ecb52616bd54a1198f249a1dab88",
"assetValue": null,
"field": "service:8443/tcp",
"previousValue": null,
"currentValue": "Apache HTTP Server 2.4.65 / TLSv1.3",
"detectedAt": "2026-09-22T20:58:43.903Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "endpoint responded on first observation",
"serviceId": null
},
{
"id": "cb805c29384268548e83d5781c24e0dd0",
"changeType": "NEW_ASSET",
"assetId": "ceb06ecb52616bd54a1198f249a1dab88",
"assetValue": null,
"field": null,
"previousValue": null,
"currentValue": "asset with 1 observed open endpoint(s)",
"detectedAt": "2026-09-22T20:58:43.901Z",
"significance": "low",
"severity": "notice",
"confidence": null,
"detail": "asset observed for the first time",
"serviceId": null
}
],
"dnsRecords": [],
"state": {
"current": {
"services": {
"8443/tcp": {
"state": "open",
"product": "Apache HTTP Server",
"version": "2.4.65",
"cert_sha256": "4a238f216d40a4a94df1a442c7aa174db1f59bdff004621635e01ce47083f3d5",
"tls_version": "TLSv1.3",
"service_type": "https-alt"
}
},
"technologies": [
"apache-http-server"
]
},
"previous": null,
"comparable": false
}
}