ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Russian hackers hijack internet traffic using vulnerable routers

mediumVulnerabilityimportance 35CVE-2023-50224

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-50224
Authentication Bypass by Spoofing in TP-Link TL-WR841N Router Exposes Stored Credentials

CVE-2023-50224 is an improper authentication flaw (CWE-290) in the httpd service of the TP-Link TL-WR841N router, which listens on TCP port 80 by default; it was reported through Trend Micro's Zero Day Initiative (ZDI-CAN-19899). A network-adjacent attacker with no credentials can send spoofed authentication data to the web interface, bypassing authentication and disclosing stored credentials (including credentials handled by the device's dropbearpwd component). The attacker gains access to sensitive stored credentials, which can be leveraged for further compromise of the router and connected networks; the flaw has high confidentiality impact but no integrity or availability impact (CVSS 6.5, adjacent-network vector). Owners of TL-WR841N routers are affected, and vendor CPE data additionally enumerates related TP-Link firmware products (e.g., MR6400, TL-WDR3600, TL-WDR4300, TL-WR740N series); no specific vulnerable version ranges were provided in the source data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-03, confirming exploitation in the wild (ransomware use unknown), although no public PoC is known.

Do: Apply firmware updates from TP-Link per vendor instructions as required by the CISA KEV listing (follow BOD 22-01 guidance), and because this is an older router line, verify whether your specific hardware revision still receives firmware, replacing or retiring devices that are end-of-life. Until patched, restrict the web management interface to trusted LAN segments, disable WAN-side/remote management on TCP port 80, and rotate admin and WAN credentials (e.g., PPPoE) that may have been disclosed.

6.516% KEV
  • tp-link tl-wr841n firmware
  • tp-link mr6400 firmware
  • tp-link tl-wdr3600 firmware
  • +9 more
masslikely millions of deployed devices (tens of millions of TL-WR841N units shipped globally; tens of thousands of TP-Link routers visible in public internet…
Full article428 words · extracted from helpnetsecurity.com · click to collapse

The Russian state cyber group APT28 has been compromising routers to hijack web traffic and spy on victims, the UK’s The National Cyber Security Centre (NCSC) has warned.

Russian hackers router hijacking

Attackers are exploiting vulnerable routers to alter DHCP and DNS settings, redirecting traffic through servers they control.

“We assess that APT28 is almost certainly the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Centre (GTsSS) Military Intelligence Unit 26165.” said NCSC.

Since 2024, APT28 has configured Virtual Private Servers (VPSs) to operate as malicious DNS infrastructure, receiving large volumes of requests from routers compromised through publicly known vulnerabilities. Investigators identified two clusters of this activity, each involving multiple servers.

“The DHCP DNS server settings of compromised small office/home office (SOHO) routers were modified to include actor-owned IP addresses. These settings were subsequently inherited by downstream devices, for example laptops and phones,” investigators wrote.

“Lookups for domain names containing key terms associated with particular services, often email applications or login pages, would then be resolved by the malicious DNS servers to further actor-owned IP addresses. DNS requests not matching the actor’s targeting criteria would instead be resolved to the legitimate IP addresses for the requested services,” they added.

This setup enabled adversary-in-the-middle activity, allowing attackers to intercept browser sessions and desktop applications and collect authentication data, including passwords and authentication tokens.

One of the router models exploited was the TP-Link WR841N, likely using CVE-2023-50224. The vulnerability allowed unauthenticated access to sensitive information through crafted requests, including credential data. After gaining access, attackers modified DHCP and DNS settings on the device to control how traffic was routed.

These changes typically replaced the primary DNS server with a malicious address while leaving the secondary server unchanged, though in some cases both entries were altered, suggesting repeated compromise.

A second cluster involved infrastructure receiving DNS requests from compromised devices, including MikroTik and TP-Link routers, and forwarding those requests to additional attacker-controlled systems. Some of this activity included operations against a small number of routers located in Ukraine.

Officials note the activity is likely opportunistic, with attackers casting a wide net before narrowing their focus to selected targets.

The NCSC issued a technical advisory on the tactics, techniques and procedures associated with APT28’s exploitation of routers to enable DNS hijacking operations.

“This activity demonstrates how exploited vulnerabilities in widely used network devices can be leveraged by sophisticated hostile actors. We strongly encourage organisations and network defenders to familiarise themselves with the techniques described in the advisory and to follow the mitigation advice,” said Paul Chichester, NCSC Director of Operations.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/04/07/russian-hackers-router-hijacking-dns-credential-theft/