TP-Link Router Flaw CVE-2023-33538 Under Active Exploit, CISA Issues Immediate Alert
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28771 | Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies. Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use. | 9.8 | 99% | KEV PoC |
| largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate | |
| CVE-2023-33538 | Command Injection in TP-Link TL-WR940N, TL-WR841N, TL-WR740N Routers CVE-2023-33538 is a command injection flaw (CWE-77) in the /userRpm/WlanNetworkRpm component of the web management interface on several legacy TP-Link routers. An attacker who can reach the router's management interface and send crafted requests to that component can cause the device to execute arbitrary operating-system commands. Successful exploitation typically gives the attacker full control of the router, enabling traffic manipulation, DNS hijacking, or pivoting into the connected network. Only the named hardware revisions are affected — TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 — and these products may be end-of-life or end-of-service, meaning fixes may be limited or unavailable. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16, indicating exploitation in the wild, and its high EPSS score (41.9%, 99th percentile) points to substantial near-term exploitation risk. Do: Inventory for these models and check the hardware version on the device label (TL-WR940N V2/V4, TL-WR841N V8/V10, TL-WR740N V1/V2), then apply TP-Link's mitigations or firmware updates per vendor instructions for that hardware version if still available. Because the products may be end-of-life or end-of-service, prioritize disabling remote/WAN access to the router's management interface, restrict it to trusted networks, and plan replacement of any unit still in service where mitigations are unavailable. CISA's required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance (for federal agencies), or discontinue use of the product. | 8.8 | 42% | KEV PoC ×2 |
| masslikely 1M+ affected devices worldwide (precise count unknown) |
Full article598 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 17, 2025Network Security / IoT Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw in TP-Link wireless routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability in question is CVE-2023-33538 (CVSS score: 8.8), a command injection bug that could result in the execution of arbitrary system commands when processing the ssid1 parameter in a specially crafted HTTP GET request.
"TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm," the agency said.
CISA has also warned that there is a possibility that affected products could be end-of-life (EoL) and/or end-of-service (EoS), urging users to discontinue their use if no mitigations are available.
There is currently no public information available about how the shortcoming is being exploited in the wild, the scale of the attacks, and who is behind them.
In December 2024, Palo Alto Networks Unit 42 revealed that it had identified additional samples of an operational technology (OT)-centric malware called FrostyGoop (aka BUSTLEBERM) and that one of the IP addresses corresponding to an ENCO control device also acted as a router web server using TP-Link WR740N to facilitate access to the ENCO device from a web browser.
However, it further pointed out that "there is no hard evidence to indicate that the attackers exploited [CVE-2023-33538] in the July 2024 FrostyGoop attack."
When reached for comment, TP-Link told The Hacker News that it has provided fixes for the vulnerability since 2018 through its tech support platform, and has urged customers to contact it in order to receive the necessary firmware updates.
"Although these product models have been discontinued since 2017, TP-Link has provided patches for this potential security flaw since 2018 through its tech support platform," the company said.
"TP-Link encourages customers who use these models to contact our tech support for patched firmware that addresses the vulnerability, or alternatively to upgrade their device with one of our supported models to ensure they can receive automatic updates for ongoing protection."
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to remediate the flaw by July 7, 2025.
New Activity Targets CVE-2023-28771
The disclosure comes as GreyNoise has warned of exploit attempts targeting a critical security flaw impacting Zyxel firewalls (CVE-2023-28771, CVSS score: 9.8).
CVE-2023-28771 refers to another operating system command injection vulnerability that could permit an unauthenticated attacker to execute commands by sending crafted requests to a susceptible device. It was patched by Zyxel in April 2023.
While the vulnerability was weaponized to build distributed denial-of-service (DDoS) botnets such as Mirai shortly after public disclosure, the threat intelligence firm said it spotted heightened attempts to exploit it as recently as June 16, 2025.
As many as 244 unique IP addresses are said to have participated in the efforts over a short timespan, with the activity targeting the United States, United Kingdom, Spain, Germany, and India.
"Historical analysis indicates that in the two weeks preceding June 16, these IPs were not observed engaging in any other scanning or exploit behavior — only targeting CVE-2023-28771," GreyNoise said, adding it identified "indicators consistent with Mirai botnet variants."
To mitigate the threat, users are recommended to update their Zyxel devices to the latest version, monitor for any anomalous activity, and limit exposure where applicable.
(The story was updated after publication to include a response from TP-Link.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/06/tp-link-router-flaw-cve-2023-33538.html