Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-20016 | MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022. NVD description · AI analysis pending | 9.8 | 86% | PoC ×2 |
| — | |
| CVE-2017-5259 | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path h In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https:// /adm/syscmd.asp. NVD description · AI analysis pending | 8.8 | 31% |
| — | ||
| CVE-2018-14558 | Unauthenticated Command Injection in Tenda AC7, AC9, and AC10 Routers CVE-2018-14558 is an unauthenticated OS command injection flaw (CWE-78) in the web interface of Tenda AC7, AC9, and AC10 routers, where the formsetUsbUnload handler passes untrusted input to the dosystemCmd function. An attacker triggers it by sending a crafted HTTP request to the goform/setUsbUnload endpoint, requiring no authentication or user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields arbitrary command execution on the router, enabling full device takeover for traffic interception, botnet enrollment, or pivoting into the local network. Anyone running AC7 firmware through V15.03.06.44_CN(AC7), AC9 firmware through V15.03.05.19(6318)_CN(AC9), or AC10 firmware through V15.03.06.23_CN(AC10) is affected. The flaw has a public proof of concept, an 8.7% EPSS (95th percentile), and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating exploitation in the wild. Do: Apply updated firmware from Tenda per vendor/CISA instructions, upgrading AC7 beyond V15.03.06.44_CN, AC9 beyond V15.03.05.19(6318)_CN, and AC10 beyond V15.03.06.23_CN. Until patched, avoid exposing the router's web management interface to the internet (disable remote/WAN management) and restrict admin access to trusted clients. Check device logs for unsolicited requests to goform/setUsbUnload as an indicator of exploitation. | 9.8 | 9% | KEV PoC |
| massplausibly 1M+ affected devices (estimate; hundreds of thousands of Tenda web interfaces appear internet-exposed in public scans) | |
| CVE-2020-25499 | TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. NVD description · AI analysis pending | 8.8 | 4% | PoC |
| — | |
| CVE-2020-8515 | Unauthenticated Command Injection RCE in DrayTek Vigor3900/2960/300B Routers CVE-2020-8515 is an unauthenticated OS command injection flaw (CWE-78) in the web management page of DrayTek Vigor3900, Vigor2960, and Vigor300B routers. An attacker can trigger it by sending crafted, unauthenticated HTTP requests to the router's management web interface, injecting shell metacharacters into commands executed by the device. Successful exploitation yields remote code execution on the router, allowing an attacker to install web shells, alter firewall/VPN settings, intercept traffic, or pivot into the protected network. Any organization running affected Vigor3900/2960/300B firmware with the management interface reachable from the internet is exposed; these models are commonly deployed as small-business and branch-office VPN gateways. The flaw is being actively exploited: CISA added it to the KEV on 2021-11-03 and EPSS assigns a 100% probability of exploitation within 30 days, though no public PoC is catalogued. Do: Upgrade Vigor3900, Vigor2960, and Vigor300B to firmware 1.5.1.1 or later per DrayTek's instructions, as required by the CISA KEV entry. Do not expose the web management page directly to the internet, and inspect internet-facing units for indicators of compromise such as unexpected web shell files (e.g., webs.php), unknown administrator accounts, or altered firewall/VPN settings. If compromise is confirmed, perform a factory reset and reflash clean firmware, then restore configurations from trusted backups. | 9.8 | 100% | KEV PoC |
| large≈10,000–100,000 internet-exposed Vigor routers (total Vigor installed base in the millions) | |
| CVE-2022-3573 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all version An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on the self-hosted instances running without strict CSP. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2022-40005 | Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTra Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute. NVD description · AI analysis pending | 8.8 | 35% | PoC ×2 |
| — | |
| CVE-2022-44149 | The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required NVD description · AI analysis pending | 8.8 | 64% | PoC ×4 |
| — | |
| CVE-2023-28771 | Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies. Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use. | 9.8 | 99% | KEV PoC |
| largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate |
Full article693 words · extracted from thehackernews.com · click to collapse
Threat actors are exploiting an unspecified zero-day vulnerability in Cambium Networks cnPilot routers to deploy a variant of the AISURU botnet called AIRASHI to carry out distributed denial-of-service (DDoS) attacks.
According to QiAnXin XLab, the attacks have leveraged the security flaw since June 2024. Additional details about the shortcomings have been withheld to prevent further abuse.
Some of the other flaws weaponized by the distributed denial-of-service (DDoS) botnet include CVE-2013-3307, CVE-2016-20016, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-3573, CVE-2022-40005, CVE-2022-44149, CVE-2023-28771, as well as those impacting AVTECH IP cameras, LILIN DVRs, and Shenzhen TVT devices.
"The operator of AIRASHI has been posting their DDoS capability test results on Telegram," XLab said. "From historical data, it can be observed that the attack capacity of the AIRASHI botnet remains stable around 1-3 Tbps."
A majority of the compromised devices are located in Brazil, Russia, Vietnam, and Indonesia, with China, the United States, Poland, and Russia becoming the primary targets of the malicious swarm.
AIRASHI is a variant of the AISURU (aka NAKOTNE) botnet that was previously flagged by the cybersecurity company in August 2024 in connection with a DDoS attack targeting Steam around the same time coinciding with the launch of the game Black Myth: Wukong.
A frequently updated botnet, select variations of AIRASHI have also been found incorporating proxyware functionality, indicating that the threat actors intend to expand their services beyond facilitating DDoS attacks.
AISURU is said to have temporarily suspended its attack activities in September 2024, only for it to reappear a month later with updated features (dubbed kitty) and refreshed again a second time at the end of November (aka AIRASHI).
"The kitty sample began spreading in early October 2024," XLab noted. "Compared to previous AISURU samples, it has simplified the network protocol. By the end of October, it started using SOCKS5 proxies to communicate with the C2 server."
AIRASHI, on the other hand, comes in at least two different flavors -
- AIRASHI-DDoS (first detected in late October), which primarily focuses on DDoS attacks, but also supports arbitrary command execution and reverse shell access
- AIRASHI-Proxy (first detected in early December), which is a modified version of AIRASHI-DDoS with proxy functionality
The botnet, in addition to continuously tweaking its methods to obtain the C2 server details via DNS queries, relies on a completely new network protocol that involves HMAC-SHA256 and CHACHA20 algorithms for communication. Furthermore, AIRASHI-DDoS supports 13 message types, while AIRASHI-Proxy supports only five message types.
The findings show that bad actors continue to exploit vulnerabilities in IoT devices both as an initial access vector and for building botnets that use them to put added weight behind powerful DDoS attacks.
The development comes as QiAnXin shed light on a cross-platform backdoor named alphatronBot that has targeted the Chinese government and enterprises to enlist infected Windows and Linux systems into a botnet. Active since the start of 2023, the malware adopted a legitimate open-source peer-to-peer (P2P) chat application named PeerChat to talk to other infected nodes.
The decentralized nature of the P2P protocol means that an attacker can issue commands through any of the compromised nodes without having to route them through a single C2 server, thus making the botnet a lot more resilient to takedowns.
"The 700+ P2P networks built into the backdoor consist of infected network device components from 80 countries and territories," the company said. "The nodes involve MikroTik routers, Hikvision cameras, VPS servers, DLink routers, CPE devices, etc."
Last year, XLab also detailed a sophisticated and stealthy payload delivery framework codenamed DarkCracks that exploits compromised GLPI and WordPress sites to function as downloaders and C2 servers.
"Its primary objectives are to gather sensitive information from infected devices, maintain long-term access, and use the compromised, stable, high-performance devices as relay nodes to control other devices or deliver malicious payloads, effectively obfuscating the attacker's footprint," it said.
"The compromised systems were found to belong to critical infrastructure across different countries, including school websites, public transportation systems, and prison visitor systems."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/01/hackers-exploit-zero-day-in-cnpilot.html