logo

A Deep Dive Into Attempted Exploitation of CVE-2023-33538

ID: 2bcc32b5-a98b-57d9-afe5-76db30adde27

STIX ID: report--2bcc32b5-a98b-57d9-afe5-76db30adde27

Feed Name: Palo Alto Networks Unit 42

Threat Score
65/100

Date Published: 2026-04-16

Date Updated: 2026-04-28

Author: Asher Davila, Malav Vyas and Chris Navarrete

...
...

This report analyzes active scan-and-exploit activity targeting CVE-2023-33538 in end-of-life TP‑Link routers: researchers emulated TL-WR940N firmware, confirmed a command‑injection vulnerability via the ssid1 parameter (requiring authentication), analyzed Mirai-like arm7 malware and its C2/update behavior, observed noisy but flawed in-the-wild exploits (wrong parameter, unauthenticated, reliant on missing utilities), and published IOCs and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.