Vulnerabilities · 145 days ago

End-of-Life TP-Link Routers Face Botnet Infection Attempts

Old TP-Link routers are not just exposed to a bug. They are exposed to automated botnet enrollment attempts, and the usual response of waiting for a patch does not apply because these models are end-of-life and have no vendor fix. The real risk is that a vulnerable router can become a foothold for persistent malware, not just a one-time crash or injection event.

Unit 42 observed active scans and probes against CVE-2023-33538 on TL-WR940N v2/v4, TL-WR740N v1/v2, and TL-WR841N v8/v10. The payloads were Mirai-like malicious binaries delivered from multiple hosts, including 51.38.137.113, bot.ddosvps.cc, and cnc.vietdediserver.shop. Their emulation work confirmed the vulnerability is real, even though the observed exploit code was flawed and would fail in the wild.

The forward risk is mass infection of unsupported routers that still sit on networks with default credentials. That makes these devices a durable entry point for botnets and DDoS infrastructure long after the original disclosure.

CVE-2023-33538

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: tP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection… EPSS 42% (99th percentile).

CISA federal remediation date Jul 7 · date passed

Timeline

Sources

7 sources covering this story

Entities

Part of the PlainSec briefing for 2026-04-20

Editions

Related stories