ZeroHour
Product

RTL81XX

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Home & Small Office Wireless Routers Exploited to Attack Gaming Servers

Unit 42 details an updated Gafgyt botnet variant exploiting Zyxel, Huawei, and Realtek router vulnerabilities to recruit devices for DoS attacks on gaming servers.

Unit 42 researchers identified an updated Gafgyt variant derived from the JenX botnet that combines three remote code execution exploits: CVE-2017-18368 (Zyxel P660HN-T1A), CVE-2017-17215 (Huawei HG532), and CVE-2014-8361 (Realtek RTL81XX chipset). Shodan scans show more than 32,000 wireless routers worldwide potentially vulnerable to these exploits. The exploits act as droppers, pulling architecture-specific binaries from a malicious server (185.172.110.224), and the botnet performs denial-of-service attacks against gaming servers, most notably Valve Source engine servers.

Related CVEs

  • Unauthenticated OS Command Injection in Zyxel/Billion TrueOnline Routers
    CVE-2017-18368 is a critical (CVSS 9.8) unauthenticated OS command injection (CWE-78) in the Remote System Log forwarding function of Zyxel P660HN-T1A (v1 and v2) and Billion 5200W-T routers distributed by Thailand ISP TrueOnline. An unauthenticated attacker who can reach the router's web management interface sends a crafted remote_host parameter to the ViewLog.asp page, with no credentials or user interaction required. Successful injection executes arbitrary operating-system commands on the device, giving the attacker full control of the router (e.g., botnet recruitment, traffic/DNS manipulation, or pivoting into the subscriber's LAN). Only TrueOnline-issued units of these models are affected, meaning Thai broadband subscribers deployed with this CPE. The flaw is in CISA's KEV catalog (added 2023-08-07), carries a 94.4% EPSS (100th percentile), and related reporting shows IoT botnets (e.g., Gafgyt campaigns against End-of-Life Zyxel routers and multi-exploit campaigns like RondoDox) actively targeting such devices.
    · Zyxel P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 (TrueOnline-distributed firmware; model listed broadly as affected by CISA) · Zyxel P660HN-T1A v2 KEV PoC ×3mass
  • Improper Input Validation in Realtek SDK miniigd SOAP Service Enables Remote RCE
    The Realtek SDK, a software development kit embedded in routers, gateways, and similar network equipment sold under many OEM brands, contains an improper input validation flaw (CWE-20) in its miniigd UPnP SOAP service. A remote, unauthenticated attacker can trigger it by sending a crafted NewInternalClient request to the vulnerable SOAP interface, causing execution of malicious code on the device. Successful exploitation gives attackers control of affected devices, which can be used for botnet recruitment, staging further attacks, or ransomware operations. Affected parties are owners of devices built on the Realtek SDK, particularly routers and gateways with the UPnP service exposed to the internet. Exploitation is ongoing: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-09-18 and EPSS assigns it a 100% probability of exploitation within 30 days, though ransomware use is not confirmed.
    · Realtek SDK KEVmass
  • Huawei HG532 with some customized versions has a remote code execution vulnerability.
    Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.
    · huawei hg532 firmware

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.