A Deep Dive Into Attempted Exploitation of CVE-2023-33538
ID: 2bcc32b5-a98b-57d9-afe5-76db30adde27
STIX ID: report--2bcc32b5-a98b-57d9-afe5-76db30adde27
Feed Name: Palo Alto Networks Unit 42
Date Published: 2026-04-16
Date Updated: 2026-04-28
Author: Asher Davila, Malav Vyas and Chris Navarrete
This report analyzes active scan-and-exploit activity targeting CVE-2023-33538 in end-of-life TP‑Link routers: researchers emulated TL-WR940N firmware, confirmed a command‑injection vulnerability via the ssid1 parameter (requiring authentication), analyzed Mirai-like arm7 malware and its C2/update behavior, observed noisy but flawed in-the-wild exploits (wrong parameter, unauthenticated, reliant on missing utilities), and published IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
