Various Botnets Pummel Year-Old TP-Link Flaw in IoT Attacks
ID: fba8df07-25fb-598c-842b-4efaf8f69d5d
STIX ID: report--fba8df07-25fb-598c-842b-4efaf8f69d5d
Feed Name: Dark Reading
Date Published: 2024-04-17
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A year-old unauthenticated command-injection flaw (CVE-2023-1389) in TP-Link Archer AX21 routers is being actively exploited by multiple botnets (Mirai variants, Moobot, Miori, Agoent, a Gafgyt variant, Condi) to compromise devices for IoT-driven DDoS and persistent control; FortiGuard researchers observed traffic spikes, detail the exploitation mechanics, enumerate IoCs (C2 servers, URLs, files), and recommend applying patches to mitigate infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
