InfectedSlurs botnet targets QNAP VioStor NVR vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-47565 | Authenticated OS Command Injection in QNAP VioStor NVR (QVR Firmware 4.x) CVE-2023-47565 is an OS command injection vulnerability (CWE-78) affecting legacy QNAP VioStor NVR models running QVR Firmware 4.x, rated 8.8 (High) on the CVSS 3.1 scale. An authenticated user can send crafted input over the network that the device passes to the underlying operating system, triggering arbitrary command execution. Successful exploitation allows the attacker to run OS commands on the NVR, which typically means full compromise of the device for data access, lateral movement, or enrollment into botnets such as the Mirai-based InfectedSlurs campaign. Only organizations still operating legacy VioStor NVR hardware on QVR 4.x are affected; QNAP fixed the vulnerability in QVR Firmware 5.0.0 and later. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, EPSS assigns a 73.3% probability of exploitation within 30 days (99th percentile), and the InfectedSlurs botnet has been reported actively targeting it. Do: Upgrade affected legacy VioStor NVRs to QVR Firmware 5.0.0 or later; per CISA's KEV required action, apply vendor mitigations or discontinue use of any unit that cannot be updated. Remove internet exposure of the NVR web interface where possible, verify the running QVR firmware version on each device, and hunt for signs of botnet infection (unusual outbound traffic or processes) given confirmed in-the-wild exploitation. | 8.8 | 73% | KEV |
| large≈tens of thousands of internet-exposed legacy VioStor NVR devices (estimate) | |
| CVE-2023-49897 | OS Command Injection in FXC AE1021/AE1021PE Routers Exploited in the Wild An OS command injection flaw (CWE-78) exists in FXC AE1021 and AE1021PE router firmware versions 2.0.9 and earlier. An attacker who is able to log in to the device can submit crafted input that the firmware passes to the underlying operating system, causing arbitrary OS commands to be executed. Successful exploitation yields arbitrary command execution on the router with high impact across confidentiality, integrity, and availability (CVSS 3.1 8.8), effectively giving the attacker control of the device. Any user or organization running AE1021 or AE1021PE firmware 2.0.9 or earlier is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, and public Akamai research ties it to a Mirai-based botnet campaign exploiting these routers for DDoS activity, with a 50.4% EPSS probability of exploitation over the next 30 days (99th percentile). Do: Upgrade AE1021 and AE1021PE devices to the latest FXC firmware (any version newer than 2.0.9), per the vendor advisory and the CISA KEV required action; if patching is not possible, discontinue use of the product or restrict its management interface to trusted networks with strong login credentials. Review devices for signs of compromise, such as unexpected outbound connections or changed credentials, since a Mirai-based botnet campaign has been observed exploiting these routers. | 8.8 | 50% | KEV PoC |
| unknown precise count; plausibly on the order of tens of thousands of deployed units |
Full article421 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 17, 2023

The Mirai-based botnet InfectedSlurs was spotted targeting QNAP VioStor NVR (Network Video Recorder) devices.
In November, Akamai warned of a new Mirai-based DDoS botnet, named InfectedSlurs, actively exploiting two zero-day vulnerabilities to infect routers and video recorder (NVR) devices.
The researchers discovered the botnet in October 2023, but they believe it has been active since at least 2022. The experts reported the two vulnerabilities to the respective vendors, but they plan to release the fixes in December 2023.
At the time, the company did not reveal the names of the impacted vendors, the researchers determined that the bot also used default admin credentials to install the Mirai variants.
A close look at the ongoing campaign revealed that the bot also targets wireless LAN routers built for hotels and residential applications.
On December 6, The Akamai Security Intelligence Response Team (SIRT) published the first update to the InfectedSlurs advisory series. The security firm revealed that threat actors were exploiting a vulnerability, tracked as CVE-2023-49897 (CVSS score 8.0) that impacted several routers, including Future X Communications (FXC) AE1021 and AE1021PE wall routers, running firmware versions 2.0.9 and earlier.
The Akamai SIRT this week published an additional update after one of the affected vendors, QNAP, released advisory information and guidance.
The experts reported that the InfectedSlurs botnet is exploiting a remote code execution (RCE) vulnerability, tracked as CVE-2023-47565 (CVSS score 8.0), in QNAP VioStor NVR (Network Video Recorder) devices.
The vulnerability affects VioStor NVR Versions 5.0.0 and earlier (5.0.0 released June 21, 2014).
“QNAP considers these devices discontinued for support; however, the vendor recommends upgrading VioStor firmware on existing devices to the latest available version. This issue had previously been patched, although it was never publicly reported/disclosed.” reads the advisory published by Akamai.
The Akamai SIRT discovered that the bot was running an exploit targeting QNAP VioStor NVR devices that were shipped with weak default credentials. Similar to the initial two zero-days, the compromised devices could exploit OS command injection vulnerabilities in NTP settings on the affected Internet of Things (IoT) and NVR devices.
“Once again, our custom honeypot network deployment has provided valuable insights into cyberattacks, revealing previously unknown vulnerabilities. The presence of default credentials and outdated, unsupported networked systems has emerged as a route for botnet infections.” concludes the report. “Legacy systems are fertile ground for new vulnerabilities to be discovered and exploited in order to propagate malware.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, InfectedSlurs botnet)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/155972/hacking/infectedslurs-botnet-qnap-viostor-nvr.html