{"id":12218,"date":"2026-04-18T10:03:36","date_gmt":"2026-04-18T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/hackers-target-tp-link-routers-with-mirai-malware-in-cve-2023-33538-exploitation-attempts\/"},"modified":"2026-04-18T10:03:36","modified_gmt":"2026-04-18T10:03:36","slug":"hackers-target-tp-link-routers-with-mirai-malware-in-cve-2023-33538-exploitation-attempts","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/18\/hackers-target-tp-link-routers-with-mirai-malware-in-cve-2023-33538-exploitation-attempts\/","title":{"rendered":"Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts"},"content":{"rendered":"<p>    Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. <\/p>\n<p>The vulnerability, tracked as CVE-2023-33538, affects multiple TP-Link models that no longer receive vendor updates, leaving users with no official patch to apply.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/94360e9d-f3d0-4b03-b702-a6a5bc174693\/Hackers-Target-TP-Link-Routers-With-Mirai-Malware-in-CVE-2023-33538-Exploitation-Attempts.pdf?AWSAccessKeyId=ASIA2F3EMEYES5DP5HUF&amp;Signature=dqGMt32Dzapv4JKBte5sd9RU5jo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBEaCXVzLWVhc3QtMSJGMEQCIGj6%2BGsngw0j%2Fb9f7nJd7V2DccNT5X2atFwTjz0kOvszAiBwxcoNqRxWA0pIjJAzH4Z%2FpyAiVl7pUojStKIKYohEIir8BAjZ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMoPH3JU77NnlxubyLKtAEfrPK6GRIktC45JC6Wps8YVPEUfTnVy4GYMQOMxHcMWw9RRftKF6A9ydzTLjZ2gOiOxpK%2FzEcj1OiMeGEHejDmYeYdnxi9aayqGnxpjqutHarAyz6iHoY9t%2Bq86xF2c7nvgjuJt38ChOPEXqXPC9xt9jiWS%2FhJ5WfCmpxv6VvGlLWJTuMOCp8EGYxxEm0yoK1s9K6M%2BWQCOr%2FdhDdeBDKDFgquaxq%2FT0h2eAXk4G071GGxlo6Ed2pLbO047AIyR0h54UoUCuy%2BDAlwSD35hSOL4Zc5gdzXO%2FVK55i%2BgfsJWew6rXQQuPLVrEccIRTRAK5Ei1spQj48DF0DHo1wx4O1EQN3h5T8VmIgYDyPXNVyx8to%2FDdRNNgbqf4Vp2H6qZQ5BbkIW5KuT%2FAOGaz2xXTsLyKkkdJZmPCh8xGbawtVNhr52QEpUddqsYvlSSma%2BSpgtVnaLkIij9xP22XI%2F2D%2BL%2BYG2C1raOzwUgyw5oSwcGXoA2znvzZzPkDwSKwdYWeu2WEXZv%2BvbiMkXCeCm6lwAWZuXfjisAHDJh7Oe4YWfkvduac8QSRmx2AK1sUOtfWV0sS3Je6cIp1DFmoYHaLy6dWfTKiNDnYSulzfh89L%2B%2Fax9WZfRAoDws6tnzy1Lt1iHgyrqxc3Dwjz92KmLvDBsXrTwRID7UnaKlzBzDZ0LHOD2F8h0%2FDnyflWtzaf28vPDsdy79GnbvssZJLFPbcRAH9%2FZbwnkvLNnRo5pRtY%2FkE%2BHPzBTKing%2FPvB4LNff0CdWqk8kKAjBadz5ZrB9KXTDwu4nPBjqZAfz3bfX5Vez5ZeXp7uLjJPMnvigjT6WDtrAe4j1VvqvCQfYxnqVx2fB2uc5oCf1edxnIykdHppqx2gM9KQsUVw3UWe5H5y5oEQxWTp8g5Fvhs1uWEKzQtQZc8hkhdO7MOyWrPgqyeEO0FS5c0bTUrUZC4t5A6OHQ3CPVfBVIDyV4tTOc2uWvJRP%2BDx4lhbik6NaaHocqdhFz9A%3D%3D&amp;Expires=1776443586\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The affected routers include the TL-WR940N (versions 2 and 4), TL-WR740N (versions 1 and 2), and TL-WR841N (versions 8 and 10). <\/p>\n<p>These devices share a common weakness in their web management interfaces, where a specific parameter inside an HTTP GET request is not properly checked for harmful content. <\/p>\n<p>This missing input validation gives attackers a clear opening to inject and run commands on the router without triggering any warning on the device.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/94360e9d-f3d0-4b03-b702-a6a5bc174693\/Hackers-Target-TP-Link-Routers-With-Mirai-Malware-in-CVE-2023-33538-Exploitation-Attempts.pdf?AWSAccessKeyId=ASIA2F3EMEYES5DP5HUF&amp;Signature=dqGMt32Dzapv4JKBte5sd9RU5jo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBEaCXVzLWVhc3QtMSJGMEQCIGj6%2BGsngw0j%2Fb9f7nJd7V2DccNT5X2atFwTjz0kOvszAiBwxcoNqRxWA0pIjJAzH4Z%2FpyAiVl7pUojStKIKYohEIir8BAjZ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMoPH3JU77NnlxubyLKtAEfrPK6GRIktC45JC6Wps8YVPEUfTnVy4GYMQOMxHcMWw9RRftKF6A9ydzTLjZ2gOiOxpK%2FzEcj1OiMeGEHejDmYeYdnxi9aayqGnxpjqutHarAyz6iHoY9t%2Bq86xF2c7nvgjuJt38ChOPEXqXPC9xt9jiWS%2FhJ5WfCmpxv6VvGlLWJTuMOCp8EGYxxEm0yoK1s9K6M%2BWQCOr%2FdhDdeBDKDFgquaxq%2FT0h2eAXk4G071GGxlo6Ed2pLbO047AIyR0h54UoUCuy%2BDAlwSD35hSOL4Zc5gdzXO%2FVK55i%2BgfsJWew6rXQQuPLVrEccIRTRAK5Ei1spQj48DF0DHo1wx4O1EQN3h5T8VmIgYDyPXNVyx8to%2FDdRNNgbqf4Vp2H6qZQ5BbkIW5KuT%2FAOGaz2xXTsLyKkkdJZmPCh8xGbawtVNhr52QEpUddqsYvlSSma%2BSpgtVnaLkIij9xP22XI%2F2D%2BL%2BYG2C1raOzwUgyw5oSwcGXoA2znvzZzPkDwSKwdYWeu2WEXZv%2BvbiMkXCeCm6lwAWZuXfjisAHDJh7Oe4YWfkvduac8QSRmx2AK1sUOtfWV0sS3Je6cIp1DFmoYHaLy6dWfTKiNDnYSulzfh89L%2B%2Fax9WZfRAoDws6tnzy1Lt1iHgyrqxc3Dwjz92KmLvDBsXrTwRID7UnaKlzBzDZ0LHOD2F8h0%2FDnyflWtzaf28vPDsdy79GnbvssZJLFPbcRAH9%2FZbwnkvLNnRo5pRtY%2FkE%2BHPzBTKing%2FPvB4LNff0CdWqk8kKAjBadz5ZrB9KXTDwu4nPBjqZAfz3bfX5Vez5ZeXp7uLjJPMnvigjT6WDtrAe4j1VvqvCQfYxnqVx2fB2uc5oCf1edxnIykdHppqx2gM9KQsUVw3UWe5H5y5oEQxWTp8g5Fvhs1uWEKzQtQZc8hkhdO7MOyWrPgqyeEO0FS5c0bTUrUZC4t5A6OHQ3CPVfBVIDyV4tTOc2uWvJRP%2BDx4lhbik6NaaHocqdhFz9A%3D%3D&amp;Expires=1776443586\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The attacks work by sending malicious HTTP GET requests to the \/userRpm\/WlanNetworkRpm endpoint. The requests carry commands embedded in the ssid parameter, which the router\u2019s firmware processes without filtering harmful input. <\/p>\n<p>Once the router accepts the request, the commands instruct it to download an ELF binary named arm7 from a remote server at IP address 51.38.137[.]113, assign it full execution permissions, and run it immediately.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/94360e9d-f3d0-4b03-b702-a6a5bc174693\/Hackers-Target-TP-Link-Routers-With-Mirai-Malware-in-CVE-2023-33538-Exploitation-Attempts.pdf?AWSAccessKeyId=ASIA2F3EMEYES5DP5HUF&amp;Signature=dqGMt32Dzapv4JKBte5sd9RU5jo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBEaCXVzLWVhc3QtMSJGMEQCIGj6%2BGsngw0j%2Fb9f7nJd7V2DccNT5X2atFwTjz0kOvszAiBwxcoNqRxWA0pIjJAzH4Z%2FpyAiVl7pUojStKIKYohEIir8BAjZ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMoPH3JU77NnlxubyLKtAEfrPK6GRIktC45JC6Wps8YVPEUfTnVy4GYMQOMxHcMWw9RRftKF6A9ydzTLjZ2gOiOxpK%2FzEcj1OiMeGEHejDmYeYdnxi9aayqGnxpjqutHarAyz6iHoY9t%2Bq86xF2c7nvgjuJt38ChOPEXqXPC9xt9jiWS%2FhJ5WfCmpxv6VvGlLWJTuMOCp8EGYxxEm0yoK1s9K6M%2BWQCOr%2FdhDdeBDKDFgquaxq%2FT0h2eAXk4G071GGxlo6Ed2pLbO047AIyR0h54UoUCuy%2BDAlwSD35hSOL4Zc5gdzXO%2FVK55i%2BgfsJWew6rXQQuPLVrEccIRTRAK5Ei1spQj48DF0DHo1wx4O1EQN3h5T8VmIgYDyPXNVyx8to%2FDdRNNgbqf4Vp2H6qZQ5BbkIW5KuT%2FAOGaz2xXTsLyKkkdJZmPCh8xGbawtVNhr52QEpUddqsYvlSSma%2BSpgtVnaLkIij9xP22XI%2F2D%2BL%2BYG2C1raOzwUgyw5oSwcGXoA2znvzZzPkDwSKwdYWeu2WEXZv%2BvbiMkXCeCm6lwAWZuXfjisAHDJh7Oe4YWfkvduac8QSRmx2AK1sUOtfWV0sS3Je6cIp1DFmoYHaLy6dWfTKiNDnYSulzfh89L%2B%2Fax9WZfRAoDws6tnzy1Lt1iHgyrqxc3Dwjz92KmLvDBsXrTwRID7UnaKlzBzDZ0LHOD2F8h0%2FDnyflWtzaf28vPDsdy79GnbvssZJLFPbcRAH9%2FZbwnkvLNnRo5pRtY%2FkE%2BHPzBTKing%2FPvB4LNff0CdWqk8kKAjBadz5ZrB9KXTDwu4nPBjqZAfz3bfX5Vez5ZeXp7uLjJPMnvigjT6WDtrAe4j1VvqvCQfYxnqVx2fB2uc5oCf1edxnIykdHppqx2gM9KQsUVw3UWe5H5y5oEQxWTp8g5Fvhs1uWEKzQtQZc8hkhdO7MOyWrPgqyeEO0FS5c0bTUrUZC4t5A6OHQ3CPVfBVIDyV4tTOc2uWvJRP%2BDx4lhbik6NaaHocqdhFz9A%3D%3D&amp;Expires=1776443586\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/unit42.paloaltonetworks.com\/exploitation-of-cve-2023-33538\/\" id=\"https:\/\/unit42.paloaltonetworks.com\/exploitation-of-cve-2023-33538\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Unit 42 analysts and researchers at Palo Alto Networks identified this malicious activity<\/a> after CISA added CVE-2023-33538 to its Known Exploited Vulnerabilities (KEV) catalog in June 2025. <\/p>\n<p>Their telemetry systems detected large-scale, automated exploitation attempts around that same period, with multiple probes targeting the same vulnerable endpoint across numerous devices in the wild.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/94360e9d-f3d0-4b03-b702-a6a5bc174693\/Hackers-Target-TP-Link-Routers-With-Mirai-Malware-in-CVE-2023-33538-Exploitation-Attempts.pdf?AWSAccessKeyId=ASIA2F3EMEYES5DP5HUF&amp;Signature=dqGMt32Dzapv4JKBte5sd9RU5jo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBEaCXVzLWVhc3QtMSJGMEQCIGj6%2BGsngw0j%2Fb9f7nJd7V2DccNT5X2atFwTjz0kOvszAiBwxcoNqRxWA0pIjJAzH4Z%2FpyAiVl7pUojStKIKYohEIir8BAjZ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMoPH3JU77NnlxubyLKtAEfrPK6GRIktC45JC6Wps8YVPEUfTnVy4GYMQOMxHcMWw9RRftKF6A9ydzTLjZ2gOiOxpK%2FzEcj1OiMeGEHejDmYeYdnxi9aayqGnxpjqutHarAyz6iHoY9t%2Bq86xF2c7nvgjuJt38ChOPEXqXPC9xt9jiWS%2FhJ5WfCmpxv6VvGlLWJTuMOCp8EGYxxEm0yoK1s9K6M%2BWQCOr%2FdhDdeBDKDFgquaxq%2FT0h2eAXk4G071GGxlo6Ed2pLbO047AIyR0h54UoUCuy%2BDAlwSD35hSOL4Zc5gdzXO%2FVK55i%2BgfsJWew6rXQQuPLVrEccIRTRAK5Ei1spQj48DF0DHo1wx4O1EQN3h5T8VmIgYDyPXNVyx8to%2FDdRNNgbqf4Vp2H6qZQ5BbkIW5KuT%2FAOGaz2xXTsLyKkkdJZmPCh8xGbawtVNhr52QEpUddqsYvlSSma%2BSpgtVnaLkIij9xP22XI%2F2D%2BL%2BYG2C1raOzwUgyw5oSwcGXoA2znvzZzPkDwSKwdYWeu2WEXZv%2BvbiMkXCeCm6lwAWZuXfjisAHDJh7Oe4YWfkvduac8QSRmx2AK1sUOtfWV0sS3Je6cIp1DFmoYHaLy6dWfTKiNDnYSulzfh89L%2B%2Fax9WZfRAoDws6tnzy1Lt1iHgyrqxc3Dwjz92KmLvDBsXrTwRID7UnaKlzBzDZ0LHOD2F8h0%2FDnyflWtzaf28vPDsdy79GnbvssZJLFPbcRAH9%2FZbwnkvLNnRo5pRtY%2FkE%2BHPzBTKing%2FPvB4LNff0CdWqk8kKAjBadz5ZrB9KXTDwu4nPBjqZAfz3bfX5Vez5ZeXp7uLjJPMnvigjT6WDtrAe4j1VvqvCQfYxnqVx2fB2uc5oCf1edxnIykdHppqx2gM9KQsUVw3UWe5H5y5oEQxWTp8g5Fvhs1uWEKzQtQZc8hkhdO7MOyWrPgqyeEO0FS5c0bTUrUZC4t5A6OHQ3CPVfBVIDyV4tTOc2uWvJRP%2BDx4lhbik6NaaHocqdhFz9A%3D%3D&amp;Expires=1776443586\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The downloaded arm7 binary is a variant of the Condi IoT botnet malware, a Mirai-based family tied to previous campaigns. Once running on the infected router, the malware connects to a command-and-control (C2) server and folds the device into a larger botnet. <\/p>\n<p>The C2 domain cnc.vietdediserver[.]shop is directly associated with these <a href=\"https:\/\/cybersecuritynews.com\/zyxel-nas-devices-under-attack\/\" id=\"68510\" target=\"_blank\" rel=\"noreferrer noopener\">Mirai-like botnet<\/a> operations and was confirmed malicious.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/94360e9d-f3d0-4b03-b702-a6a5bc174693\/Hackers-Target-TP-Link-Routers-With-Mirai-Malware-in-CVE-2023-33538-Exploitation-Attempts.pdf?AWSAccessKeyId=ASIA2F3EMEYES5DP5HUF&amp;Signature=dqGMt32Dzapv4JKBte5sd9RU5jo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBEaCXVzLWVhc3QtMSJGMEQCIGj6%2BGsngw0j%2Fb9f7nJd7V2DccNT5X2atFwTjz0kOvszAiBwxcoNqRxWA0pIjJAzH4Z%2FpyAiVl7pUojStKIKYohEIir8BAjZ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMoPH3JU77NnlxubyLKtAEfrPK6GRIktC45JC6Wps8YVPEUfTnVy4GYMQOMxHcMWw9RRftKF6A9ydzTLjZ2gOiOxpK%2FzEcj1OiMeGEHejDmYeYdnxi9aayqGnxpjqutHarAyz6iHoY9t%2Bq86xF2c7nvgjuJt38ChOPEXqXPC9xt9jiWS%2FhJ5WfCmpxv6VvGlLWJTuMOCp8EGYxxEm0yoK1s9K6M%2BWQCOr%2FdhDdeBDKDFgquaxq%2FT0h2eAXk4G071GGxlo6Ed2pLbO047AIyR0h54UoUCuy%2BDAlwSD35hSOL4Zc5gdzXO%2FVK55i%2BgfsJWew6rXQQuPLVrEccIRTRAK5Ei1spQj48DF0DHo1wx4O1EQN3h5T8VmIgYDyPXNVyx8to%2FDdRNNgbqf4Vp2H6qZQ5BbkIW5KuT%2FAOGaz2xXTsLyKkkdJZmPCh8xGbawtVNhr52QEpUddqsYvlSSma%2BSpgtVnaLkIij9xP22XI%2F2D%2BL%2BYG2C1raOzwUgyw5oSwcGXoA2znvzZzPkDwSKwdYWeu2WEXZv%2BvbiMkXCeCm6lwAWZuXfjisAHDJh7Oe4YWfkvduac8QSRmx2AK1sUOtfWV0sS3Je6cIp1DFmoYHaLy6dWfTKiNDnYSulzfh89L%2B%2Fax9WZfRAoDws6tnzy1Lt1iHgyrqxc3Dwjz92KmLvDBsXrTwRID7UnaKlzBzDZ0LHOD2F8h0%2FDnyflWtzaf28vPDsdy79GnbvssZJLFPbcRAH9%2FZbwnkvLNnRo5pRtY%2FkE%2BHPzBTKing%2FPvB4LNff0CdWqk8kKAjBadz5ZrB9KXTDwu4nPBjqZAfz3bfX5Vez5ZeXp7uLjJPMnvigjT6WDtrAe4j1VvqvCQfYxnqVx2fB2uc5oCf1edxnIykdHppqx2gM9KQsUVw3UWe5H5y5oEQxWTp8g5Fvhs1uWEKzQtQZc8hkhdO7MOyWrPgqyeEO0FS5c0bTUrUZC4t5A6OHQ3CPVfBVIDyV4tTOc2uWvJRP%2BDx4lhbik6NaaHocqdhFz9A%3D%3D&amp;Expires=1776443586\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"inside-the-arm7-malware-binary\"><strong>Inside the Arm7 Malware Binary<\/strong><\/h2>\n<p>After gaining access to the device, the arm7 binary carries out a structured set of tasks to maintain its presence and grow the botnet. <\/p>\n<p>It waits for specific byte-pattern commands from the C2 server and responds by sending heartbeat signals, triggering self-updates, and launching internal HTTP server functions.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqm-hGRYR0uwfWcfpGcGJpV3LMHHahbzmIwE1GEBklSVj2hyphenhyphenCFHiguEgcGkD8hCXUh2oqzTzAkg-IIs7SVxlwFEltMrzuJHns9y9wKDsBRhE0pxpxKzeGoaFaPyHc2zTvTGr72Tc8MkHMLGqPLZ73D6tFqYliLwjGRDZTf-mq5y4_ZO1uk7UNbZ4bVztU\/s16000\/An%2520example%2520of%2520an%2520exploit%2520attempt%2520for%2520CVE-2023-33538%2520that%2520we%2520observed%2520in%2520May%25202025%2520%28Source%2520-%2520Unit42%29.webp?ssl=1\" alt=\"An example of an exploit attempt for CVE-2023-33538 that we observed in May 2025 (Source - Unit42)\"><figcaption class=\"wp-element-caption\">An example of an exploit attempt for CVE-2023-33538 that we observed in May 2025 (Source \u2013 Unit42)<\/figcaption><\/figure>\n<p>One particularly notable behavior is the self-update routine. The binary uses the update_bins() function to connect back to 51.38.137[.]113 on TCP port 80 and pull fresh copies of itself built for eight different CPU architectures, including arm6, mips, sh4, and x86_64. <\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/whats-the-difference-between-a-mac-address-and-an-ip-address\/\" id=\"84137\" target=\"_blank\" rel=\"noreferrer noopener\">IP address<\/a> and port are hard-coded directly inside the binary, as confirmed during disassembly. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiTx-g8FU5sEtrVSXTRozBPgl13PBKgph_4vbq74-0DctXgAvxiOiL9gDZVEXz_NPOeAIgWkjrDzPYV3VLlGP9WH8zCSC2jpsvdx5N8DYBnSmvF8MQ1oZcDB5zD6oDWOVu-fsWnTVbP8B642BeYdFGfb229ePPBqSOR0tRSWZBWJfv4nx3maZ1Hzmel9bY\/s16000\/The%2520update_bins%2520function%2520with%2520a%2520hard-coded%2520IP%2520address%2520and%2520port%2520%28Source%2520-%2520Unit42%29.webp?ssl=1\" alt=\"The update_bins function with a hard-coded IP address and port (Source - Unit42)\"><figcaption class=\"wp-element-caption\">The update_bins function with a hard-coded IP address and port (Source \u2013 Unit42)<\/figcaption><\/figure>\n<\/div>\n<p>The arm7 binary also starts an HTTP server on the infected device using a port randomly chosen between 1024 and 65535. <\/p>\n<p>Once active, this server delivers fresh malware copies to other devices that connect to it, spreading the infection further without requiring any additional input from the attacker. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj0w6Ws0chvpvrSTWbD-oP0hPG1JtuhkGrvKbYx3snpKYi0HvP8X49bX0c4220cNDFrg3FN3bL57V9ZuUic-7MdaOyp7puUKus_hhRQ4NzzHnDE-dgIcFiWnk8cDllcPvhHhB5rLS6VKjazY02S1BV8rcQLUQ6_HhL1U6wBFhOgVUug1G0Ma1WZCAmFkeQ\/s16000\/httpd_start%28%29%2520function%2520graph%2520for%2520the%2520arm7%2520binary%2520%28Source%2520-%2520Unit42%29.webp?ssl=1\" alt=\"httpd_start() function graph for the arm7 binary (Source - Unit42)\"><figcaption class=\"wp-element-caption\">httpd_start() function graph for the arm7 binary (Source \u2013 Unit42)<\/figcaption><\/figure>\n<\/div>\n<p>This allows each newly infected host to go on recruiting more victims. Despite their scale, the in-the-wild exploit attempts observed by researchers carried technical errors. <\/p>\n<p>The attackers targeted the ssid parameter rather than the correct and vulnerable ssid1 parameter, and their injected commands depended on wget, a utility absent from the router\u2019s limited BusyBox environment. <\/p>\n<p>Even so, the research team confirmed that the underlying vulnerability is real and that a more accurate attacker using the correct parameter could successfully exploit it.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/94360e9d-f3d0-4b03-b702-a6a5bc174693\/Hackers-Target-TP-Link-Routers-With-Mirai-Malware-in-CVE-2023-33538-Exploitation-Attempts.pdf?AWSAccessKeyId=ASIA2F3EMEYES5DP5HUF&amp;Signature=dqGMt32Dzapv4JKBte5sd9RU5jo%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEBEaCXVzLWVhc3QtMSJGMEQCIGj6%2BGsngw0j%2Fb9f7nJd7V2DccNT5X2atFwTjz0kOvszAiBwxcoNqRxWA0pIjJAzH4Z%2FpyAiVl7pUojStKIKYohEIir8BAjZ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMoPH3JU77NnlxubyLKtAEfrPK6GRIktC45JC6Wps8YVPEUfTnVy4GYMQOMxHcMWw9RRftKF6A9ydzTLjZ2gOiOxpK%2FzEcj1OiMeGEHejDmYeYdnxi9aayqGnxpjqutHarAyz6iHoY9t%2Bq86xF2c7nvgjuJt38ChOPEXqXPC9xt9jiWS%2FhJ5WfCmpxv6VvGlLWJTuMOCp8EGYxxEm0yoK1s9K6M%2BWQCOr%2FdhDdeBDKDFgquaxq%2FT0h2eAXk4G071GGxlo6Ed2pLbO047AIyR0h54UoUCuy%2BDAlwSD35hSOL4Zc5gdzXO%2FVK55i%2BgfsJWew6rXQQuPLVrEccIRTRAK5Ei1spQj48DF0DHo1wx4O1EQN3h5T8VmIgYDyPXNVyx8to%2FDdRNNgbqf4Vp2H6qZQ5BbkIW5KuT%2FAOGaz2xXTsLyKkkdJZmPCh8xGbawtVNhr52QEpUddqsYvlSSma%2BSpgtVnaLkIij9xP22XI%2F2D%2BL%2BYG2C1raOzwUgyw5oSwcGXoA2znvzZzPkDwSKwdYWeu2WEXZv%2BvbiMkXCeCm6lwAWZuXfjisAHDJh7Oe4YWfkvduac8QSRmx2AK1sUOtfWV0sS3Je6cIp1DFmoYHaLy6dWfTKiNDnYSulzfh89L%2B%2Fax9WZfRAoDws6tnzy1Lt1iHgyrqxc3Dwjz92KmLvDBsXrTwRID7UnaKlzBzDZ0LHOD2F8h0%2FDnyflWtzaf28vPDsdy79GnbvssZJLFPbcRAH9%2FZbwnkvLNnRo5pRtY%2FkE%2BHPzBTKing%2FPvB4LNff0CdWqk8kKAjBadz5ZrB9KXTDwu4nPBjqZAfz3bfX5Vez5ZeXp7uLjJPMnvigjT6WDtrAe4j1VvqvCQfYxnqVx2fB2uc5oCf1edxnIykdHppqx2gM9KQsUVw3UWe5H5y5oEQxWTp8g5Fvhs1uWEKzQtQZc8hkhdO7MOyWrPgqyeEO0FS5c0bTUrUZC4t5A6OHQ3CPVfBVIDyV4tTOc2uWvJRP%2BDx4lhbik6NaaHocqdhFz9A%3D%3D&amp;Expires=1776443586\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Regarding recommendations, TP-Link confirmed the affected devices are end-of-life and no vendor patches will be made available. The company advises users to replace these units with currently supported hardware. <\/p>\n<p>Changing the default admin:admin login credentials is also strongly recommended, as exploitation of this vulnerability requires authenticated access to the router\u2019s web interface. <\/p>\n<p>Administrators should monitor <a href=\"https:\/\/cybersecuritynews.com\/attaxion-releases-agentless-traffic-monitoring-for-immediate-risk-prioritization\/\" id=\"123027\" target=\"_blank\" rel=\"noreferrer noopener\">outbound traffic<\/a> for connections to known malicious domains and retire any affected TP-Link router models still active on their networks.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-target-tp-link-routers\/\">Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-target-tp-link-routers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. The vulnerability, tracked as CVE-2023-33538, affects multiple TP-Link models that no longer receive vendor updates, leaving users with no [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12218","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12218"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12218"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12218\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12218"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12218"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12218"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}