End-of-Life TP-Link Routers Face Botnet Infection Attempts
Old TP-Link routers are not just exposed to a bug. They are exposed to automated botnet enrollment attempts, and the usual response of waiting for a patch does not apply because these models are end-of-life and have no vendor fix. The real risk is that a vulnerable router can become a foothold for persistent malware, not just a one-time crash or injection event.
Unit 42 observed active scans and probes against CVE-2023-33538 on TL-WR940N v2/v4, TL-WR740N v1/v2, and TL-WR841N v8/v10. The payloads were Mirai-like malicious binaries delivered from multiple hosts, including 51.38.137.113, bot.ddosvps.cc, and cnc.vietdediserver.shop. Their emulation work confirmed the vulnerability is real, even though the observed exploit code was flawed and would fail in the wild.
The forward risk is mass infection of unsupported routers that still sit on networks with default credentials. That makes these devices a durable entry point for botnets and DDoS infrastructure long after the original disclosure.