TP-Link Router Botnet
TP-Link路由器存在严重安全漏洞(CVE-2023-1389),导致命令注入和远程代码执行,被用于传播恶意软件如Mirai、Condi和AndroxGh0st。感染设备主要集中在巴西、波兰等国,并针对美、中等国的制造业、医疗和科技机构发起攻击。 2025-3-14 11:2:58 Author: www.schneier.com(查看原文) 阅读量:6 收藏

TP-Link Router Botnet

There is a new botnet that is infecting TP-Link routers:

The botnet can lead to command injection which then makes remote code execution (RCE) possible so that the malware can spread itself across the internet automatically. This high severity security flaw (tracked as CVE-2023-1389) has also been used to spread other malware families as far back as April 2023 when it was used in the Mirai botnet malware attacks. The flaw also linked to the Condi and AndroxGh0st malware attacks.

[…]

Of the thousands of infected devices, the majority of them are concentrated in Brazil, Poland, the United Kingdom, Bulgaria and Turkey; with the botnet targeting manufacturing, medical/healthcare, services and technology organizations in the United States, Australia, China and Mexico.

Details.

Tags: ,

Posted on March 14, 2025 at 7:02 AM3 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/03/tp-link-router-botnet.html
如有侵权请联系:admin#unsafe.sh