Vulnerability record · CVE-2020-8656 · published 7 February 2020
CVE-2020-8656: EyesOfNetwork API SQL injection allows unauthenticated auth bypass
EEyesofnetwork · Eyesofnetwork
The EyesOfNetwork API 2.4.2 in EyesOfNetwork 5.3 is vulnerable to SQL injection in the username field passed to getApiKey in include/api_functions.php. Because the flaw is reachable without authentication, it exposes the monitoring platform's API to direct compromise.
Description
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with CVSS 9.8, very high EPSS and public exploit references makes this an urgent patch target.
What it is
The EyesOfNetwork API 2.4.2 in EyesOfNetwork 5.3 is vulnerable to SQL injection in the username field passed to getApiKey in include/api_functions.php. Because the flaw is reachable without authentication, it exposes the monitoring platform's API to direct compromise.
Impact
An attacker can bypass authentication and obtain an API key, then perform actions available to the API, with the CVSS vector indicating high confidentiality, integrity and availability impact.
Attack surface
Reachable over the network through the EyesOfNetwork API endpoint handling getApiKey in include/api_functions.php; no authentication or user interaction is required per the CVSS vector and description.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.846, ~99.7th percentile) and public references are tagged Exploit, including a remote code execution write-up, so exploitation is feasible and likely.
What to do
- Apply the vendor fix or upgrade EyesOfNetwork/eonapi beyond the affected 5.3 / API 2.4.2 versions.
- Restrict network access to the EyesOfNetwork API to trusted management networks only.
- Use parameterized queries or strict input validation for the username field in getApiKey.
- Rotate API keys and credentials that may have been exposed through the API.
- Monitor and alert on anomalous API authentication attempts against getApiKey.
Detection
- Inspect web and API logs for requests to getApiKey with SQL metacharacters or boolean/UNION patterns in the username parameter.
- Alert on successful API key retrieval from unexpected source IPs or without prior legitimate authentication.
- Review EyesOfNetwork API and database logs for SQL error messages or unusual query behavior.
- Hunt for post-exploitation activity consistent with the published remote code execution chain on EyesOfNetwork hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/EyesOfNetworkCommunity/eonapi/issues/16 | Third Party Advisory |
| http://packetstormsecurity.com/files/156266/EyesOfNetwork-5.3-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/156605/EyesOfNetwork-AutoDiscovery-Target-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/EyesOfNetworkCommunity/eonapi/issues/16 | Third Party Advisory |
Track CVE-2020-8656 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-8656), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.