Most recent
navigate open esc close Corpus index built 2026-06-07 23:58 UTC

← All engagement records

Case study May 1, 2026

ITMO University, Russia: 24 Models, gpt-oss:20b + gpt-oss:120b Cloud Proxies

Sector
Universities
Country
itmo

NuClide Research · 2026-05-01


Summary

ITMO University (Saint Petersburg, Russia) has an Ollama instance with 24 models including frontier models (Llama 4, Qwen 2.5 VL 72B, Kimi-Dev-72B) and gpt-oss:20b / gpt-oss:120b cloud proxies. No credential leak detected on active probe, likely paid-tier. Unauthenticated inference against all 24 models.


Infrastructure

FieldValue
IP77.234.216.105
rDNS, (NXDOMAIN)
OrgITMO University (verified via Shodan ASN)
CountryRussia
Open ports11434 (Ollama, public)

Models (24 total)

ModelSizeNotes
gpt-oss:20b12 GB☁️ Cloud proxy candidate
gpt-oss:120b60 GB☁️ Cloud proxy candidate
volker-mauel/Kimi-Dev-72B-GGUF:q8_071 GBKimi Dev coding model
llama4:16x17b62 GBLlama 4 MoE
llama4:latest62 GBLlama 4
qwen2.5vl:72b65 GBVision-language
qwen3.6:35b22 GB
qwen3.5:27b16 GB
qwen3:32b18 GB
qwen3:8b4 GB
mistral-small3.2:24b14 GB
mistral-small3.1:latest14 GB
mistral-small3.1:24b14 GB
mistral-small3.1-24b-128k:latest14 GB
mistral-small:24b13 GB
mixtral:8x7b24 GB
gemma3:27b16 GB
granite3.2-vision:2b2 GB
llama3:70b37 GB
deepseek-r1:70b39 GB
qwen3-vl:8b5 GB
qwen3-vl:4b3 GB
llama3.2:3b1 GB
smollm2:135m0 GB

Findings

F1, Unauthenticated Ollama API (CRITICAL): 24 models including 71GB Kimi-Dev, 65GB VL, and multiple 60GB+ frontier models accessible without credentials.

F2, Cloud Proxy Presence (HIGH): gpt-oss:20b and gpt-oss:120b present. Probe timed out, status (free-tier 200 OK vs paid 401) unconfirmed.

F3, Model Injection (HIGH): All 24 models injectable via CVE-2025-63389.


Disclosure

  • Discovered: 2026-05-01
  • Status: Pending outreach to ITMO CERT