Security News > 2025 > March > TP-Link Router Botnet

TP-Link Router Botnet
2025-03-14 11:02

There is a new botnet that is infecting TP-Link routers: The botnet can lead to command injection which then makes remote code execution (RCE) possible so that the malware can spread itself across the internet automatically. This high severity security flaw (tracked as CVE-2023-1389) has also been used to spread other malware families as far back as April 2023 when it was used in the Mirai botnet malware attacks. The flaw also linked to the Condi and AndroxGh0st malware attacks. […] Of the thousands of infected devices, the majority of them are concentrated in Brazil, Poland, the United Kingdom, Bulgaria and Turkey; with the botnet targeting manufacturing, medical/healthcare, services and technology organizations in the United States, Australia, China and Mexico...


News URL

https://www.schneier.com/blog/archives/2025/03/tp-link-router-botnet.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-03-15 CVE-2023-1389 Command Injection vulnerability in Tp-Link Archer Ax21 Firmware
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form of the /cgi-bin/luci;stok=/locale endpoint on the web management interface.
low complexity
tp-link CWE-77
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
TP Link 323 0 75 171 88 334