ZeroHour
The Recordpublished ()ingested

Mirai botnet hackers targeting TP-Link router zero

criticalMalwareimportance 60CVE-2023-1389

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-1389
Command Injection in TP-Link Archer AX21 Router Allows Remote Code Execution

CVE-2023-1389 is a command injection flaw (CWE-77) in TP-Link's Archer AX21 Wi-Fi 6 router that lets an attacker execute arbitrary operating-system commands on the device. It is triggered by sending crafted input to a remotely reachable service on the router, which passes attacker-controlled values to the device's shell without proper sanitization; the source data does not specify the vulnerable endpoint or exact affected firmware ranges. Successful exploitation yields remote code execution on the router, giving the attacker a foothold in the network where the router sits, from which they can pivot or abuse the device further. Any household or organization running an Archer AX21 router is affected, with the highest risk where the router's management interface is exposed to the internet. The flaw was added to CISA's KEV catalog on 2023-05-01, confirming exploitation in the wild; EPSS assigns a ~100% probability of exploitation within 30 days (top percentile), while no public proof-of-concept or ransomware association is documented in the source data.

Do: Update the Archer AX21 to the latest firmware available from TP-Link per the vendor's instructions (fixed firmware is published on the product's TP-Link support page). If updating is not immediately possible, disable WAN-side/remote management and restrict the router's web interface to the local network. Because exploitation is confirmed in the wild, also review exposed routers for signs of compromise, such as unexplained configuration changes or unexpected outbound traffic.

8.8100% KEV PoC ×2
  • TP-Link Archer AX21 (Archer AX-21) Wi-Fi 6 router
masslikely hundreds of thousands of routers deployed, with >100k plausibly internet-exposed
Full article479 words · extracted from therecord.media · click to collapse

Hackers are using a new zero-day vulnerability to attack a line of TP-Link routers based primarily in Eastern Europe and add them to the Mirai botnet.

The vulnerability – CVE-2023-1389 – was discovered last December at the Pwn2Own Toronto event. It affects the TP-Link Archer AX21, a popular brand of router available to most consumers for under $90. It opens the door for the infamous Mirai malware, which compromises a variety of devices and adds them to a botnet — a network of infected computers that can be used to knock websites and other services offline.

Major router manufacturers like the Hong Kong-based TP-Link have long been a target of Mirai hackers, who frequently use new vulnerabilities to exploit devices and add them to their botnet.

The Hong Kong-based company patched the vulnerability in March, but now a team from Trend Micro’s Zero Day Initiative (ZDI) has discovered “that exploit attempts using this CVE were detected in the wild.”

“Starting on April 11, we began seeing notifications from our telemetry system that a threat actor had started to publicly exploit this vulnerability,” ZDI said in a blog post.

“Most of the initial activity was seen attacking devices that are in Eastern Europe, but we are now observing detections in other locations around the globe.”

The researchers found several ties to Mirai infrastructure and tools used by the hackers to take over devices.

One specific feature is a functionality that allows the device to be used in distributed denial-of-service (DDoS) attacks against game servers. DDoS attacks flood targeted websites with junk traffic, making them unreachable.

The hackers also use other features to make traffic from the device look legitimate, making it more difficult to identify the DDoS traffic.

But what alarmed ZDI researchers most was how quickly the vulnerability was added to the hackers’ toolkit.

“Seeing this CVE being exploited so quickly after the patch being released is a clear demonstration of the decreasing ‘time-to-exploit’ speed that we continue to see across the industry,” they wrote.

“That said, this is nothing new for the maintainers of the Mirai botnet, who are known for quickly exploiting IoT [internet-of-things] devices to maintain their foothold in an enterprise.”

Researchers are constantly discovering new variants of the Mirai malware, most recently in February. The botnet was first discovered in August 2016 and has been used to facilitate some of the most disruptive distributed DDoS attacks on record.

That year, it used more than 100,000 infected devices to launch a DDoS attack on the Domain Name System provider Dyn.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/mirai-botnet-hackers-targeting-tplink