logo

Various Botnets Pummel Year-Old TP-Link Flaw in IoT Attacks

ID: fba8df07-25fb-598c-842b-4efaf8f69d5d

STIX ID: report--fba8df07-25fb-598c-842b-4efaf8f69d5d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-04-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

A year-old unauthenticated command-injection flaw (CVE-2023-1389) in TP-Link Archer AX21 routers is being actively exploited by multiple botnets (Mirai variants, Moobot, Miori, Agoent, a Gafgyt variant, Condi) to compromise devices for IoT-driven DDoS and persistent control; FortiGuard researchers observed traffic spikes, detail the exploitation mechanics, enumerate IoCs (C2 servers, URLs, files), and recommend applying patches to mitigate infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.