newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: TP-Link router defective CVE-2023-33538 Under active exploits, CISA will issue alerts immediately
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > TP-Link router defective CVE-2023-33538 Under active exploits, CISA will issue alerts immediately
Technology

TP-Link router defective CVE-2023-33538 Under active exploits, CISA will issue alerts immediately

June 17, 2025 3 Min Read
Share
TP-Link router defective CVE-2023-33538 Under active exploits, CISA will issue alerts immediately
SHARE

The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added high-strength security flaws in TP-Link wireless routers to its known Exploited Vulnerabilities (KEV) catalogue, citing evidence of aggressive exploitation.

The vulnerability in question is CVE-2023-33538 (CVSS score: 8.8). This is a command injection bug that could cause arbitrary system commands to be executed when processing SSID1 parameters in a specially created HTTP GET request.

“TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain command injection vulnerabilities via component/USERRPM/WLANNETWORKRPM.”

CISA also warns that the affected products may be end-of-life (EOL) and/or termination of service (EOS), urging users to discontinue use if mitigation is not available.

Currently there is no public information on how the flaws are exploited in the wild.

In December 2024, Palo Alto Networks Unit 42 identified an additional sample of malware centered around an operational technology (OT) called Frostygooop (aka Bustleberm), and revealed that one of the IP addresses corresponding to the ENCO controlled devices acted as a Router web server using the TP link WR740N, accessed from the ENCO device from the Web Browser.

However, he further pointed out that “there is no difficult evidence that the attackers exploited the attack on Frostigup in July 2024.”

Hacker news has been contacted TP-Link for more details. If you’ve heard of it, update the story. In light of active exploitation, federal agencies must fix the defects by July 7, 2025.

The new activity is targeting CVE-2023-28771

Disclosure occurs as Greynoise warned of attempts to exploit targeting critical security flaws affecting the Zyxel firewall (CVE-2023-28771, CVSS score: 9.8).

CVE-2023-28771 refers to a vulnerability in other operating system command injection. This allows unauthorized attackers to execute commands by sending craft requests to sensitive devices. Zyxel applied the patch in April 2023.

See also  Fake Docusign, gitcode site spreads net support rats via multi-stage power shell attack

The vulnerability was weaponized to build a DDOS botnet such as Mirai shortly after its public disclosure, but the threat intelligence company said it had discovered a growing attempt to exploit it in the same way as on June 16, 2025.

As many as 244 unique IP addresses are said to have participated in a short effort, with activities targeting the US, UK, Spain, Germany and India.

“Historical analysis shows that two weeks before June 16th, these IPs were not observed to be engaged in other scans or misuse behaviors, saying they were targeting CVE-2023-28771 only.

To mitigate threats, users are advised to update their Zyxel devices to the latest version, monitor for unusual activity, and limit exposure if applicable.

Share This Article
Facebook Twitter Copy Link
Previous Article Raptors are “happily” to trade some important roles for “important roster upgrades.” Raptors are “happily” to trade some important roles for “important roster upgrades.”
Next Article NASA warns that climates around the world are becoming more dramatic NASA warns that climates around the world are becoming more dramatic
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

Popular Chrome Extensions leak API keys, user data over HTTP, and hardcoded credentials
Technology

Popular Chrome Extensions leak API keys, user data over HTTP, and hardcoded credentials

5 Min Read
Anubis ransomware encrypts and wipes files, making recovery impossible even after payment
Technology

Anubis ransomware encrypts and wipes files, making recovery impossible even after payment

4 Min Read
How PHI-4 Renersing redefines AI reasoning by challenging the “Bigger Better” myth
Technology

How PHI-4 Renersing redefines AI reasoning by challenging the “Bigger Better” myth

11 Min Read
Malicious Peep, NPM and Ruby Packages exposed in an ongoing open source supply chain attack
Technology

Malicious Peep, NPM and Ruby Packages exposed in an ongoing open source supply chain attack

9 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?