CVE-2023-33538
Known exploited · CISA KEV
CVSS 8.8 HIGH: tP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection… EPSS 42% (99th percentile).
CISA federal remediation date Jul 7 · date passed
Vulnerabilities · 145 days ago
Old TP-Link routers are not just exposed to a bug. They are exposed to automated botnet enrollment attempts, and the usual response of waiting for a patch does not apply because these models are end-of-life and have no vendor fix. The real risk is that a vulnerable router can become a foothold for persistent malware, not just a one-time crash or injection event.
Unit 42 observed active scans and probes against CVE-2023-33538 on TL-WR940N v2/v4, TL-WR740N v1/v2, and TL-WR841N v8/v10. The payloads were Mirai-like malicious binaries delivered from multiple hosts, including 51.38.137.113, bot.ddosvps.cc, and cnc.vietdediserver.shop. Their emulation work confirmed the vulnerability is real, even though the observed exploit code was flawed and would fail in the wild.
The forward risk is mass infection of unsupported routers that still sit on networks with default credentials. That makes these devices a durable entry point for botnets and DDoS infrastructure long after the original disclosure.
Known exploited · CISA KEV
CVSS 8.8 HIGH: tP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection… EPSS 42% (99th percentile).
CISA federal remediation date Jul 7 · date passed
7 sources covering this story
New Mirai campaign exploits RCE flaw in EoL D-Link routers
A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet.
New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
Security researchers have documented new Mirai variants leveraged in campaigns exploiting command injection flaws in consumer IoT devices.
Attackers Exploit DVR Command Injection Flaw to Deploy Botnet
FortiGuard Labs has identified a Mirai-based Nexcorium campaign actively exploiting CVE-2024-3721 in TBK DVR devices
Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers
In-the-wild exploitation has been ongoing for a year, but no successful payload execution has been observed.
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
CVE-2024-3721 and CVE-2023-33538 exploited in TBK DVRs and EoL TP-Link routers, enabling Mirai variants and DDoS risk.
TP-Link routers face exploitation attempt linked to high-severity flaw
Researchers warn a potential botnet is targeting a vulnerability in end-of-life devices.
A Deep Dive Into Attempted Exploitation of CVE-2023-33538
CVE-2023-33538 allows for command injection in TP-Link routers.
Part of the PlainSec briefing for 2026-04-20