The blast radius is bigger than one router flaw. C0XMO is built to hop from a DD-WRT router into other IoT and embedded devices by matching the payload to the chip inside the box, so patching one product family does not stop spread across mixed fleets. The usual single-device response misses that the infection layer is portable.
Fortinet says the botnet is actively exploiting CVE-2021-27137 on DD-WRT routers. It has builds for ARM, MIPS, PowerPC, SuperH, x86, x86_64, and other architectures, and it has been seen with targets that include DVRs, routers, video management platforms, and Android-based devices. It also keeps itself alive with cron jobs and startup changes, and it can knock out rival malware on an infected host.
For operators of exposed routers, cameras, DVRs, and edge gear, the risk is not just one compromised device. Once a foothold exists, the framework can keep pushing into nearby systems that share weak SSH or telnet exposure and the same management habits.