Unit 42 researchers investigated active exploitation attempts targeting CVE-2023-33538, a command injection vulnerability in end-of-life TP-Link routers (TL-WR940N, TL-WR740N, TL-WR841N). Using firmware emulation and reverse engineering of the httpd binary, they confirmed the vulnerability is real but found the in-the-wild

19m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Our Telemetry FindingsMalware DownloadedCVE-2023-33538 Exploit Analysis

Sort: