CVE-2023-33538 under attack for a year, but exploitation still unsuccessful
ID: 1bf7facc-0094-592e-bbc7-8883c9006f47
STIX ID: report--1bf7facc-0094-592e-bbc7-8883c9006f47
Feed Name: Security Affairs
The report details attempts to exploit CVE-2023-33538 (a command-injection flaw in TP-Link routers) over more than a year: Palo Alto Networks observed large-scale scanning and exploit attempts, including delivery of a Mirai-like "arm7" binary that contacts C2 servers and can distribute updates and payloads, but found that attacks failed in practice due to authentication requirements, targeting the wrong parameter (ssid vs ssid1), and the limited BusyBox environment lacking utilities like wget.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
