Potential SAP NetViewer Webshell Command Execution — Detection Rule

Detects potential command execution via webshell in SAP NetViewer through JSP files with cmd parameter. This rule is created to detect exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution via a webshell.

Read the full analysis on IntelFusions