Analysis of Flawed CVE-2023-33538 Exploitation Attempts on TP-Link Routers
Unit 42 from Palo Alto Networks conducted a deep-dive investigation into active exploitation attempts targeting CVE-2023-33538, a command injection vulnerability in several end-of-life TP-Link Wi-Fi router models. The analysis was triggered by the addition of this CVE to CISA’s Known Exploited Vulnerabilities Catalog in June 2025. Researchers observed large-scale automated scans using payloads characteristic of Mirai-like botnet malware, specifically a variant associated with the Condi IoT botnet. These attacks attempted to download and execute malicious binaries via unsanitized HTTP GET requests. However, firmware emulation and reverse engineering revealed that the observed in-the-wild exploits were flawed and would fail to execute successfully. Despite this, the study confirmed the underlying vulnerability is real and requires authentication to the router's web interface. The risk remains significant due to the widespread use of default IoT credentials like admin:admin. TP-Link confirmed that affected devices are end-of-life with no patches available, recommending users replace the hardware and avoid default credentials to mitigate potential infection vectors.
Wire timeline
Analysis of Flawed CVE-2023-33538 Exploitation Attempts on TP-Link Routers
Unit 42 from Palo Alto Networks conducted a deep-dive investigation into active exploitation attempts targeting CVE-2023-33538, a command injection vulnerability in several end-of-life TP-Link Wi-Fi router models. The analysis was triggered by the addition of this CVE to CISA’s Known Exploited Vulnerabilities Catalog in June 2025. Researchers observed large-scale automated scans using payloads characteristic of Mirai-like botnet malware, specifically a variant associated with the Condi IoT botnet. These attacks attempted to download and execute malicious binaries via unsanitized HTTP GET requests. However, firmware emulation and reverse engineering revealed that the observed in-the-wild exploits were flawed and would fail to execute successfully. Despite this, the study confirmed the underlying vulnerability is real and requires authentication to the router's web interface. The risk remains significant due to the widespread use of default IoT credentials like admin:admin. TP-Link confirmed that affected devices are end-of-life with no patches available, recommending users replace the hardware and avoid default credentials to mitigate potential infection vectors.
Unit 42