logo

CVE-2023-33538 under attack for a year, but exploitation still unsuccessful

ID: 1bf7facc-0094-592e-bbc7-8883c9006f47

STIX ID: report--1bf7facc-0094-592e-bbc7-8883c9006f47

Feed Name: Security Affairs

Threat Score
55/100

Date Published: 2026-04-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

The report details attempts to exploit CVE-2023-33538 (a command-injection flaw in TP-Link routers) over more than a year: Palo Alto Networks observed large-scale scanning and exploit attempts, including delivery of a Mirai-like "arm7" binary that contacts C2 servers and can distribute updates and payloads, but found that attacks failed in practice due to authentication requirements, targeting the wrong parameter (ssid vs ssid1), and the limited BusyBox environment lacking utilities like wget.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.