ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2013-5223
Authenticated Cross-Site Scripting (XSS) in D-Link DSL-2760U Gateway

CVE-2013-5223 is a cross-site scripting vulnerability (CWE-79) in the web management interface of the D-Link DSL-2760U gateway, which CISA describes as allowing remote authenticated users to inject arbitrary web script or HTML. An attacker holding valid credentials for the router's administration pages (typically on the LAN, or wherever the admin interface is exposed) inserts crafted script or HTML that then executes in the browsers of other users of that interface. Successful injection can expose or hijack administrative sessions and steal credentials, and can be combined with additional requests to tamper with or reconfigure the device. Only the D-Link DSL-2760U is identified as affected; the available data provides no affected firmware version range. Although no public proof-of-concept is cataloged, CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-25 (ransomware use unknown), confirming exploitation in the wild, and EPSS assigns a 33.6% probability of exploitation within 30 days (98th percentile).

Do: Per the CISA KEV required action, apply firmware updates per D-Link's instructions; since this data specifies no affected versions, confirm with the vendor whether current DSL-2760U firmware is available and replace end-of-life units that can no longer be updated. As an interim mitigation, restrict the administration interface to the trusted LAN (disable remote/WAN management), use strong admin credentials, and review router logs and configuration for unexpected changes.

34% KEV
  • D-Link DSL-2760U
largetens of thousands to low hundreds of thousands of DSL-2760U gateways plausibly still deployed (order of magnitude ~100,000 devices; estimate only)
CVE-2015-2051
Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router

The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life.

Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation.

97% KEV
  • D-Link DIR-645 Wired/Wireless Router
largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution)
CVE-2016-11021
Authenticated OS Command Injection in D-Link DCS-930L Cameras Allows RCE

D-Link DCS-930L network cameras running firmware versions before 2.12 contain an OS command injection flaw (CWE-78) in the setSystemCommand handler. An attacker with access to the camera's web interface (the CVSS vector requires high privileges, indicating an authenticated, admin-level request) submits an operating-system command in the SystemCommand parameter, and the device executes it without proper validation. Successful exploitation yields remote code execution on the camera, enabling device takeover, pivoting into the local network, or recruitment into IoT botnets such as BotenaGo, which bundles 33 exploits targeting millions of consumer IoT devices. Any DCS-930L deployment on pre-2.12 firmware is affected, and the product is end-of-life, so CISA's required action is to disconnect it if still in use. The flaw is listed in CISA's KEV catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries a 68.9% EPSS probability of exploitation within 30 days (99th percentile), indicating confirmed in-the-wild exploitation; ransomware use is unknown.

Do: Update affected DCS-930L cameras to firmware 2.12 or later if obtainable; because the product is end-of-life, CISA's required action is to disconnect or retire any unit still in service. Until remediated, keep the camera's management interface off direct internet exposure and restrict administrative access. Verify the running firmware version and watch for signs of compromise such as unexpected outbound traffic.

7.269% KEV PoC
  • D-Link DCS-930L network camera firmware All firmware versions before 2.12 (fixed in 2.12)
largetens of thousands of internet-exposed cameras (millions of units sold historically; many EOL devices still deployed)
CVE-2016-1555
Unauthenticated Command Injection RCE in NETGEAR Business Wireless Access Points

CVE-2016-1555 is a critical (CVSS 9.8) unauthenticated command injection flaw (CWE-77) in the boardData102.php, boardData103.php, boardDataJP.php, boardDataNA.php, and boardDataWW.php management pages of seven NETGEAR wireless access point models. An attacker who can reach these web endpoints over the network can pass crafted input to the scripts and execute arbitrary operating-system commands on the access point, with no login, privilege, or user interaction required. Successful exploitation grants full control of the device, letting attackers use it as a foothold or conscript it into IoT botnets such as BotenaGo, which reportedly uses 33 exploits to target millions of IoT devices. Only the NETGEAR WN604 (firmware before 3.3.3) and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 (firmware before 3.5.5.0) are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), has a public proof-of-concept on Exploit-DB, and carries an EPSS score of 98.3%, so defenders should treat it as actively exploited in the wild.

Do: Upgrade the WN604 to firmware 3.3.3 or later and the WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 to firmware 3.5.5.0 or later, per NETGEAR's instructions. Until patched, do not expose these access points' web management interface to the internet and restrict administration to a trusted management VLAN or VPN; if current firmware is no longer obtainable for a given model, consider isolating or replacing the device. Review device and web-server logs for suspicious requests to the boardData*.php endpoints as a sign of attempted or successful exploitation.

9.898% KEV PoC
  • NETGEAR WN604 wireless access point firmware before 3.3.3
  • NETGEAR WN802Tv2 wireless access point firmware before 3.5.5.0
  • NETGEAR WNAP210v2 wireless access point firmware before 3.5.5.0
  • +4 more
largeorder of tens of thousands of internet-exposed devices; total installed base unknown
CVE-2016-6277
Unauthenticated RCE via Command Injection in NETGEAR Multiple Routers

Multiple NETGEAR router models allow unauthenticated web pages to pass form input directly to the device's command-line interface, which permits remote code execution (CVE-2016-6277). An attacker triggers the flaw by sending a crafted HTTP request to the router's web interface without logging in, causing attacker-supplied input to be interpreted as commands on the router. Successful exploitation grants the ability to run arbitrary commands on the device, typically with root privileges, enabling full takeover of the router and use as a pivot point into the network behind it. Any NETGEAR router among the affected models running firmware without the vendor patch is vulnerable, with internet-facing management interfaces at greatest risk. The flaw was added to CISA's Known Exploited Vulnerability catalog on 2022-03-07, indicating exploitation in the wild, and it carries a very high 99.8% EPSS probability of exploitation within 30 days.

Do: Update affected NETGEAR routers to the latest available firmware for the specific model, per the vendor's upgrade instructions, as required by CISA's KEV listing. As interim mitigation, disable WAN-side/remote management and restrict the router's admin interface to the local network, then review devices for signs of compromise such as unexpected configuration changes or added accounts.

8.8100% KEV PoC ×3
  • NETGEAR
masslikely 100,000+ internet-exposed NETGEAR routers (exact count unknown)
CVE-2017-18368
Unauthenticated OS Command Injection in Zyxel/Billion TrueOnline Routers

CVE-2017-18368 is a critical (CVSS 9.8) unauthenticated OS command injection (CWE-78) in the Remote System Log forwarding function of Zyxel P660HN-T1A (v1 and v2) and Billion 5200W-T routers distributed by Thailand ISP TrueOnline. An unauthenticated attacker who can reach the router's web management interface sends a crafted remote_host parameter to the ViewLog.asp page, with no credentials or user interaction required. Successful injection executes arbitrary operating-system commands on the device, giving the attacker full control of the router (e.g., botnet recruitment, traffic/DNS manipulation, or pivoting into the subscriber's LAN). Only TrueOnline-issued units of these models are affected, meaning Thai broadband subscribers deployed with this CPE. The flaw is in CISA's KEV catalog (added 2023-08-07), carries a 94.4% EPSS (100th percentile), and related reporting shows IoT botnets (e.g., Gafgyt campaigns against End-of-Life Zyxel routers and multi-exploit campaigns like RondoDox) actively targeting such devices.

Do: Update affected routers to the latest firmware available from Zyxel/Billion or via TrueOnline's ISP update process, noting these models are End-of-Life so hardware replacement is the durable fix. Until patched, restrict or disable WAN-side access to the router's web management interface (the flaw is reachable unauthenticated via ViewLog.asp) and audit devices for signs of botnet compromise. Per the CISA KEV required action, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.894% KEV PoC ×3
  • Zyxel P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 (TrueOnline-distributed firmware; model listed broadly as affected by CISA)
  • Zyxel P660HN-T1A v2
  • Billion 5200W-T
mass≈1 million (order-of-magnitude estimate) TrueOnline-issued devices, of which thousands to tens of thousands expose the management interface to the internet at…
CVE-2017-6077
Command Injection RCE in NETGEAR DGN2200 Router ping.cgi

ping.cgi on NETGEAR DGN2200 routers running firmware through version 10.0.0.50 fails to sanitize the ping_IPAddr field of HTTP POST requests, allowing shell metacharacters to inject arbitrary operating-system commands (CWE-78, OS command injection). Per the vulnerability description, an attacker needs authenticated access to the router's web interface to send the crafted POST request, although the CVSS vector treats the flaw as exploitable over the network without privileges — significant because many deployed routers use default or weak admin credentials. Successful exploitation yields arbitrary command execution on the device, enabling full router compromise, manipulation of DNS or routing, interception of traffic, and pivoting into the local network. All NETGEAR DGN2200 (Wireless Router) units on affected firmware are exposed, particularly those with the management interface reachable from the WAN. The flaw is actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-07, carries a high exploitation probability (EPSS 68.2%, 99th percentile), and a public proof-of-concept is available (Exploit-DB 41394).

Do: Upgrade DGN2200 firmware to a version later than 10.0.0.50 per NETGEAR's guidance, as required by the CISA KEV listing; if the device is end-of-life and no fixed firmware is available, plan replacement. As interim mitigations, disable WAN-side remote management, restrict the admin interface to trusted hosts, and replace default credentials, since authenticated access is the trigger. Check web server logs for HTTP POST requests to ping.cgi containing shell metacharacters in the ping_IPAddr parameter.

9.868% KEV PoC
  • NETGEAR DGN2200 Wireless Router (ping.cgi web interface) firmware through 10.0.0.50 (inclusive)
largeon the order of tens of thousands of internet-exposed DGN2200 routers (legacy ISP-bundled ADSL units); total deployed base likely higher
CVE-2017-6334
Authenticated OS Command Injection in NETGEAR DGN2200 dnslookup.cgi

The dnslookup.cgi endpoint on NETGEAR DGN2200 devices running firmware through 10.0.0.50 does not properly sanitize the host_name field, allowing shell metacharacters submitted in an HTTP POST request to be executed as OS commands on the router. A remote attacker who can authenticate to the web interface (the flaw requires valid credentials but no user interaction) gains arbitrary command execution with the device's privileges, enabling full compromise of the gateway including configuration changes, traffic manipulation, and botnet recruitment. All DGN2200-series devices on firmware 10.0.0.50 or earlier are affected, and the product line is end-of-life, so no patched firmware is expected. Exploitation is established: the flaw carries a 72.2% EPSS score, has three public PoC exploits on Exploit-DB, was added to the CISA KEV catalog on 2022-03-25, and was included among the 33 exploits used by the BotenaGo botnet targeting millions of IoT devices.

Do: Because the DGN2200 is end-of-life with no fixed firmware available, CISA's required action is to disconnect or replace the device if it is still in use. If replacement must be deferred, do not expose the router's web management interface to the internet, use strong and unique admin credentials, and review logs for unexpected authenticated POST requests to dnslookup.cgi containing metacharacters.

8.872% KEV PoC ×3
  • NETGEAR DGN2200 series firmware (dnslookup.cgi) all firmware through 10.0.0.50
mass≈ millions of consumer DSL gateways historically deployed (widely bundled by ISPs; now EOL, unknown how many remain in service)
CVE-2018-10088
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

NVD description · AI analysis pending
9.840% PoC ×2
  • xiongmaitech uc-httpd
CVE-2018-10562
+1 in the same advisory: …10561
Unauthenticated RCE in Dasan GPON Routers (CVE-2018-10562)

CVE-2018-10562 is an OS command injection flaw (CWE-78) in the web management interface of Dasan GPON home routers. When chained with the companion authentication bypass CVE-2018-10561, a remote, unauthenticated attacker can send crafted requests that execute arbitrary commands on the device. Successful exploitation yields full control of the router, enabling device takeover, botnet enrollment, and, per CISA, use in ransomware operations. Anyone operating an affected Dasan GPON router — many of which were deployed by internet service providers — is affected, and CISA notes the impacted products are end-of-life. Exploitation is confirmed in the wild: the flaw is in CISA's KEV (added 2022-03-31) with known ransomware use and a 100% EPSS probability of exploitation within 30 days.

Do: Because the product line is end-of-life and CISA's required action is to disconnect impacted devices if still in use, retire or replace affected routers rather than patching in place. If replacement must wait, block or firewall the web management interface from the internet, check the device for signs of compromise, and ensure the related authentication-bypass path CVE-2018-10561 is also closed.

9.8100% KEV ransomware PoC ×2
  • Dasan Gigabit Passive Optical Network (GPON) routers
mass≈1 million internet-exposed devices (public scan counts around the 2018 disclosure)
CVE-2019-19824
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI

On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control over the device's internals. This affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, N100RE through 3.4.0, and N302RE 2.0.2.

NVD description · AI analysis pending
8.825% PoC ×4
  • totolink a3002ru firmware
  • totolink a702r firmware
  • totolink n301rt firmware
  • +1 more
CVE-2020-10173
Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnosti

Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m devices have Multiple Authenticated Command Injection vulnerabilities via the ping and traceroute diagnostic pages, as demonstrated by shell metacharacters in the pingIpAddress parameter to ping.cgi.

NVD description · AI analysis pending
8.877% PoC
  • comtrend vr-3033 firmware
CVE-2020-10987
Unauthenticated OS Command Injection in Tenda AC15 AC1900 Router

CVE-2020-10987 is an unauthenticated OS command injection flaw (CWE-78) in the goform/setUsbUnload endpoint of the Tenda AC15 AC1900 router, demonstrated on firmware version 15.03.05.19. An attacker triggers it by sending a crafted deviceName POST parameter to that endpoint, which is not properly sanitized before being used in a system command. Successful exploitation yields arbitrary remote code execution on the router, giving the attacker full control of the device and a foothold to pivot into the local network, as is typical for IoT botnet recruitment. Owners of Tenda AC15 routers are affected, with greatest risk on units whose web administration interface is reachable from the internet. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 79.8% EPSS score (top percentile), and a public proof of concept has been available since its 2020 disclosure; ransomware use is unknown.

Do: Apply the latest Tenda AC15 firmware available from the vendor (newer than 15.03.05.19) per CISA's required action and vendor instructions. Until patched, disable or restrict WAN-side remote web administration to trusted source IPs, since the flaw is exploitable without credentials over the network. Check router HTTP logs for unexpected POST requests to /goform/setUsbUnload containing suspicious deviceName values, and monitor for botnet-style command activity.

9.880% KEV PoC
  • Tenda AC15 AC1900 router firmware Firmware version 15.03.05.19 (the only version named in the advisory; the full affected version range is not specified, so other AC15 firmware releases may also
moderateLikely on the order of thousands to tens of thousands of remotely exploitable Tenda AC15 units (estimate; no authoritative install-base or scan count provided).
CVE-2020-8515
Unauthenticated Command Injection RCE in DrayTek Vigor3900/2960/300B Routers

CVE-2020-8515 is an unauthenticated OS command injection flaw (CWE-78) in the web management page of DrayTek Vigor3900, Vigor2960, and Vigor300B routers. An attacker can trigger it by sending crafted, unauthenticated HTTP requests to the router's management web interface, injecting shell metacharacters into commands executed by the device. Successful exploitation yields remote code execution on the router, allowing an attacker to install web shells, alter firewall/VPN settings, intercept traffic, or pivot into the protected network. Any organization running affected Vigor3900/2960/300B firmware with the management interface reachable from the internet is exposed; these models are commonly deployed as small-business and branch-office VPN gateways. The flaw is being actively exploited: CISA added it to the KEV on 2021-11-03 and EPSS assigns a 100% probability of exploitation within 30 days, though no public PoC is catalogued.

Do: Upgrade Vigor3900, Vigor2960, and Vigor300B to firmware 1.5.1.1 or later per DrayTek's instructions, as required by the CISA KEV entry. Do not expose the web management page directly to the internet, and inspect internet-facing units for indicators of compromise such as unexpected web shell files (e.g., webs.php), unknown administrator accounts, or altered firewall/VPN settings. If compromise is confirmed, perform a factory reset and reflash clean firmware, then restore configurations from trusted backups.

9.8100% KEV PoC
  • DrayTek Vigor3900 firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory); CISA lists 'Multiple Vigor Routers'
  • DrayTek Vigor2960 firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory)
  • DrayTek Vigor300B firmware prior to the vendor fix (v1.5.1.1 per DrayTek's advisory)
large≈10,000–100,000 internet-exposed Vigor routers (total Vigor installed base in the millions)
CVE-2020-8958
Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary O

Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the boaform/admin/formPing Dest IP Address field.

NVD description · AI analysis pending
7.247% PoC ×2
  • gpononu 1ge router wifi onu v2801rw firmware
  • gpononu 1ge\+3fe\+wifi onu v2804rgw firmware
CVE-2020-9054
Pre-Authentication OS Command Injection in Zyxel NAS Devices

CVE-2020-9054 is a pre-authentication OS command injection flaw (CWE-78) in multiple Zyxel network-attached storage (NAS) devices. A remote, unauthenticated attacker can send crafted input to the devices' web interface to inject and execute arbitrary OS commands without logging in, resulting in remote code execution on the NAS. Successful exploitation gives the attacker control of the device, which can be used to access, alter or destroy stored data and to pivot into the network the NAS is attached to. Organizations and users running affected Zyxel NAS models are at risk, especially where the management web interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, confirming exploitation in the wild; EPSS assigns a 100% probability of exploitation within 30 days, while no public proof-of-concept is known and any ransomware use is unconfirmed.

Do: Apply the firmware updates specified in Zyxel's advisory, per CISA's required action, prioritizing any NAS whose web interface is exposed to the internet. Until patched, restrict the NAS management interface to trusted networks or VPN access and do not expose the admin UI directly to the internet. Because exploitation is confirmed in the wild, check affected devices for indicators of compromise, such as unexpected accounts, scheduled jobs, or outbound connections.

9.8100% KEV PoC
  • Zyxel
moderateplausibly tens of thousands of affected devices installed worldwide, with only a low-thousands subset directly internet-exposed
CVE-2020-9377
OS Command Injection RCE in D-Link DIR-610 Routers

D-Link DIR-610 routers contain an OS command injection flaw (CWE-78) in command.php, where the cmd parameter is passed to the underlying operating system without adequate sanitization, allowing remote attackers to execute arbitrary commands on the device. The flaw is triggered by sending a crafted HTTP request to command.php with a malicious cmd parameter. Successful exploitation yields remote command execution on the router, which an attacker can leverage for device takeover or as a foothold into the network behind it. Only D-Link DIR-610 devices, a consumer router line that has reached end-of-life, are affected. The vulnerability is listed in the CISA KEV catalog (added 2022-03-25), indicating it is being exploited in the wild, and its high EPSS percentile (97th, 21.3% probability of exploitation in 30 days) reinforces elevated risk despite no known public proof-of-concept.

Do: Disconnect or replace DIR-610 routers, which are end-of-life, consistent with CISA's required action; no fixed firmware version is specified in the available data. If replacement is not immediate, block WAN access to the router web interface (including command.php) and review logs for suspicious requests carrying a cmd parameter that could indicate compromise.

8.821% KEV PoC ×2
  • D-Link DIR-610 devices
moderateLikely a few thousand internet-exposed units (estimate; no public scan count specific to DIR-610)

Indicators of compromiseAll →

TypeIndicatorContext
ipv41.4.2.11.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices CVE-2015-2051 D-Link DIR-645 W
Full article702 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 12, 2021

Researchers at AT&T discovered a new BotenaGo botnet that is using thirty three exploits to target millions of routers and IoT devices.

BotenaGo is a new botnet discovered by researchers at AT&T that leverages thirty three exploits to target millions of routers and IoT devices.

Below is the list of exploits used by the bot:

Vulnerability Affected devices
CVE-2020-8515DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices
CVE-2015-2051D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier
CVE-2016-1555Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0
CVE-2017-6077NETGEAR DGN2200 devices with firmware through 10.0.0.50
CVE-2016-6277NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000
CVE-2018-10561, CVE-2018-10562GPON home routers
CVE-2013-3307Linksys X3000 1.0.03 build 001
CVE-2020-9377D-Link DIR-610
CVE-2016-11021D-Link DCS-930L devices before 2.12
CVE-2018-10088XiongMai uc-httpd 1.0.0
CVE-2020-10173Comtrend VR-3033 DE11-416SSG-C01_R02.A2pvI042j1.d26m
CVE-2013-5223D-Link DSL-2760U Gateway
CVE-2020-8958Guangzhou 1GE ONU V2801RW 1.9.1-181203 through 2.9.0-181024 and V2804RGW 1.9.1-181203 through 2.9.0-181024
CVE-2019-19824TOTOLINK Realtek SDK based routers, this affects A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0.
CVE-2020-10987Tenda AC15 AC1900 version 15.03.05.19
CVE-2020-9054Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.2, Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2
CVE-2017-18368ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline
CVE-2014-2321ZTE F460 and F660 cable modems
CVE-2017-6334 NETGEAR DGN2200 devices with firmware through 10.0.0.50

BotenaGo was written in Golang (Go) and at the time of the report published by the experts, it had a low antivirus (AV) detection rate (6/62).

“To deliver its exploit, the malware first queries the target with a simple “GET” request. It then searches the returned data from the “GET” request with each system signature that was mapped to attack functions.” reads the analysis published by AT&T.

“The string “Server: Boa/0.93.15” is mapped to the function “main_infectFunctionGponFiber,” which attempts to exploit a vulnerable target, allowing the attacker to execute an OS command via a specific web request (CVE-2020-8958).”

The botnet targets millions of devices with functions that exploit the above flaws, for example querying Shodan for the string Boa, which is a discontinued open-source web server used in embedded applications, it returns nearly two million devices.

Once installed, the bot malware will listen on the ports 31412 and 19412, the latter is used to receive the victim IP.

botenago

Once a connection with information to that port is received, it will loop through mapped exploit functions and execute them with the given IP.

The BotenaGo will execute remote shell commands on compromised devices, depending on the infected system, the bot uses different links associated with different payloads. Alien Labs could not analyze any of payloads because they were no more available on the hosting server.

The researchers didn’t find an active C2 communication between BotenaGo and C2 server, these are possible scenarios hypothesized by the experts:

  1. The malware is part of a “malware suite” and BotenaGo is only one module of infection in an attack. In this case, there should be another module either operating BotenaGo (by sending targets) or just updating the C&C with a new victim’s IP.
  2. The links used for the  payload on a successful attack imply a connection with Mirai malware. It could be the BotenaGo is a new tool used by Mirai operators on specific machines that are known to them, with the attacker(s) operating the infected end-point with targets.
  3. This malware is still in beta phase and has been accidently leaked.

Researchers provided the indicators of compromise associated with these attacks, they speculate the malware could be enhanced integrating new exploits.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, BotenaGo)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/124503/malware/botenago-botnet.html