Multiple botnets exploiting one-year-old TP-Link flaw to hack routers
ID: ccd256b1-9bf2-5bb8-935a-bb1904d9756a
STIX ID: report--ccd256b1-9bf2-5bb8-935a-bb1904d9756a
Feed Name: Bleeping Computer
Multiple botnet operations — including Mirai variants, AGoent, Gafgyt, Moobot, Miori, and Condi — are actively exploiting CVE-2023-1389, an unauthenticated command-injection flaw in TP-Link Archer AX21 routers; despite a firmware patch issued in March 2023, Fortinet telemetry shows surge activity since March 2024 with daily infection attempts often exceeding 40,000, enabling DDoS participation, persistence, and credential brute-forcing on unpatched devices, and users are advised to apply updates, change default admin passwords, and disable web admin access if unnecessary.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
