TP-Link Routers Hit by Mirai in CVE-2023-33538 Attacks
ID: 12ccc8c8-d392-579e-bc95-cf5215f70203
STIX ID: report--12ccc8c8-d392-579e-bc95-cf5215f70203
Feed Name: GBHackers
Hackers are scanning internet-exposed, end-of-life TP-Link routers (TL-WR940N v2/v4, TL-WR740N v1/v2, TL-WR841N v8/v10) for a command-injection flaw (CVE-2023-33538) in the web admin interface, attempting to deliver a Mirai-like payload (arm7) that can convert devices into DDoS bots; although many in-the-wild attempts are currently flawed (wrong field, missing authenticated session, lack of download utilities), researchers confirm the vulnerability is real and exploitable with valid credentials, and vendors advise replacing affected hardware, disabling remote management, and enforcing strong unique admin passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
