Exposed Admin Panel Scanners
Admin panels exposed to the internet are prime targets for credential-stuffing and brute-force attacks. These scanners locate control panels, dashboards, and management UIs that are inadvertently public.
Important Exposed Panels Scanners
phpMyAdmin Panel Detection Scanner
This scanner detects the use of phpMyAdmin Panel in digital assets.
Grafana Login Detection Scanner
Grafana Login Detection Scanner
Gitlab Panel Detection Scanner
This scanner detects the use of Gitlab Panel in digital assets.
Portainer Panel Detection Scanner
This scanner detects the use of Portainer Panel in digital assets. It identifies the presence of Portainer login panels, which can be beneficial for security assessments.
Webmin Panel Detection Scanner
This scanner detects the use of Webmin Panel in digital assets.
cPanel Detection Scanner
This scanner detects the use of cPanel API Codes panel in digital assets.
CyberPanel - Command Injection
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.
CtrlPanel <= 1.1.1 - Remote Code Execution
CtrlPanel versions
Control Web Panel (CWP) - File Inclusion
In CWP (Control Web Panel, previously CentOS Web Panel) before version 0.9.8.1107, an unauthenticated attacker can abuse null byte (%00) injection with the "scripts" parameter in the /user/loader.php or /user/login.php endpoints to register arbitrary API keys or access sensitive files. This can be exploited by using multiple %00 sequences to traverse directories via crafted requests such as /user/loader.php?api=1&scripts=.%00./.%00./api/account_new_create&acc=guadaapi, or similar payloads with more %00 instances (e.g., .%00%00%00./.%00%00%00./api/account_new_create). Attackers may use this flaw for arbitrary file access, privilege escalation, or remote code execution.
cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
cPanel and WHM versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
Vue Vben Admin - Default Credentials
Vue Vben Admin 2.10.1 contains a broken authentication caused by hardcoded credentials in the backend, letting attackers log in without proper authorization, exploit requires access to the login interface.
Four-Faith F3x36 - Authentication Bypass
Four-Faith F3x36 router with firmware v2.0.0 contains an authentication bypass caused by hard-coded credentials in the administrative web server, letting attackers with knowledge of credentials gain administrative access via crafted HTTP requests.
IBM MobileFirst Foundation - Default Credentials
Detected IBM MobileFirst Foundation Operations Console was found using default credentials. The administration REST API exposes full control over mobile application backends including adapter management, push notification infrastructure, OAuth security configuration, and application authenticity enforcement.
Homebridge - Default Admin Credentials
Detected Homebridge UI was found using default administrator credentials (admin:admin). An attacker could have gained full access to manage HomeKit accessories, plugins, and server configuration.
WordPress Loginizer < 1.6.4 - Unauthenticated SQL Injection via `log` Parameter
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_failed and lz_valid_ip.
Acronis Cyber Infrastructure - Default Password
Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, 5.1.1-71, 5.2.1-69, 5.3.1-53, and 5.4.4-132 contain a remote command execution caused by use of default passwords, letting attackers execute arbitrary commands remotely, exploit requires access to the system with default credentials.
RabbitMQ AMQP - Default Login
RabbitMQ server accepts connections with weak or default credentials over the AMQP 0-9-1 protocol (port 5672).Default credentials (guest/guest) or commonly used weak passwords were found, allowing unauthorized access to the message broker, its queues, exchanges, and all data flowing through them.
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege Escalation
Privilege escalation vulnerability exists in the Frontend Login and Registration Blocks plugin for WordPress (versions
Open WebUI - Default Login
Detected the presence of an OpenWebUI panel with default credentials (admin@localhost/admin). Successful authentication using these default credentials allows attackers to access the admin interface and potentially perform remote code execution by defining a custom "tool".
IBM Data Risk Manager - Hardcoded Credentials
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID- 180534.
FatPipe WARP/IPVPN/MPVPN - Backdoor Account
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 contain an account named "cmuser" with administrative privileges and no password, letting attackers gain unauthorized admin access, exploit requires no authentication.
Tattile Camera < 1.181.5 - Default Login
Tattile Smart+, Vega, and Basic device families firmware
Checkmk - Default Login
Checkmk monitoring instance is accessible with default credentials (cmkadmin/cmkadmin). This provides full administrative access to the monitoring platform, including the ability to view all monitored hosts, execute commands on agents, and access stored credentials.
Alibaba Sentinel - Default Login
Alibaba Sentinel versions 1.6.0 and later may expose a basic login interface with default credentials sentinel/sentinel. This template checks for that default login behavior on affected versions.
WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion
The Clean Login plugin for WordPress up to version 1.14.5 contains a path traversal caused by the 'template' attribute in the clean-login-register shortcode, letting authenticated attackers with contributor access include and execute arbitrary files, exploit requires attacker to have contributor or higher access level.
Motive eSIM Secure Connect Panel Detection Scanner
This scanner detects the use of Motive eSIM Secure Connect Panel in digital assets. It identifies exposed panels that could lead to information disclosure or unauthorized control over IoT/mobile connectivity services.
Apache Superset - Default Login
Apache Superset instance discovered using weak default credentials, allows the attacker to gain admin privilege.
GUDE - Default Login
GUDE 2301 and 2302 default administrator login credentials (admin:admin) were detected.
AstrBot - Default Login
AstrBot contains a default login vulnerability. An attacker can access the AstrBot dashboard using default credentials and gain control over the chatbot framework, modify configurations, manage LLM providers, and execute unauthorized operations.
Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials
Apache Solr 9.4.0 through 9.10.1 and 10.0.0 contain a hardcoded credentials vulnerability caused by default Basic Authentication template users in bin/solr auth enable, letting remote attackers gain full administrative access. Exploit requires use of default template users.
Cyber Stealer C2 Panel - Detect
Cyber Stealer C2 Login Panel was discovered.
NH C2 Server Detection Scanner
Identify the stealthy NH C2 Server within your network. The scanner detects the presence of command and control servers that may be utilized in malicious activities, offering valuable insights for security personnel to take necessary actions.
PupyC2 Detection Scanner
Identify the stealthy PupyC2 within your network. This scanner helps in early detection of PupyC2 activity, providing crucial insights for preventing further exploitation and maintaining network integrity.
Brute Ratel C4 Detection Scanner
Identify the stealthy Brute Ratel C4 within your network. This scanner helps detect unauthorized C2 activities, ensuring your organization's network stays protected from potential threats and evasion tactics.
EvilGinx Detection Scanner
Identify the stealthy EvilGinx within your network. This scanner helps in detecting the presence of EvilGinx C2 framework activities, criticial for ensuring the authentication and security protocols remain uncompromised.
Ares RAT C2 Panel Detection Scanner
Identify the stealthy Ares RAT C2 Panel within your network. Detect potential unauthorized access and maintain security by identifying this Remote Access Tool effectively. Ensure your systems are protected from RAT-related threats.
OXF Phishing as a Service Panel - Detect
OXF Phishing as a Service Panel was discovered.
Mystic Stealer Detection Scanner
Identify the stealthy Mystic Stealer within your network. This tool is essential for detecting unauthorized remote access, ensuring your systems are protected against threats from remote administration tools.
Hack5 Cloud C2 Detection Scanner
Identify the stealthy Hack5 Cloud C2 within your network. This scanner helps detect the presence of a command and control center used for managing Hak5 gear. Ensure your network security by identifying potential threats.
Supershell C2 Detection Scanner
Identify the stealthy Supershell C2 within your network. This scanner detects the presence of the Supershell Command and Control channel, providing valuable insights into potential security risks.
Viper C2 Detection Scanner
Identify the stealthy Viper C2 within your network. This scanner helps detect and mitigate potential threats by recognizing Viper C2's presence and activities.
Graylog - Default Admin Credentials
Detected that Graylog was using the default credentials admin:admin. The VM/OVA appliance shipped with admin:admin out of the box.
Deimos C2 Detection Scanner
Identify the stealthy Deimos C2 Command & Control tool within your network. This scanner detects and analyzes the presence of the Deimos C2 platform to ensure the security of compromised machines across various operating systems.
Rhadamanthys Stealer C2 Panel Detection Scanner
Identify the stealthy Rhadamanthys Stealer C2 Panel within your network. This scanner helps in detecting malicious command and control activities associated with Rhadamanthys Stealer, ensuring your network's safety by identifying unwanted intrusions.
Meduza Stealer Panel Detection Scanner
Identify the stealthy Meduza Stealer Panel or C2 within your network. Confirm the RAT activities and protect your systems efficiently with precise detection mechanisms provided by the scanner.
Bofamet Stealer C2 Panel - Detect
Bofamet Stealer C2 Login Panel was discovered
Run all Exposed Panels checks at once.
S4E covers 1,676+ scanners in this category with continuous monitoring and full remediation guidance.
Start Free Scan →