


Perceptive Security
SOC/SIEM Consultancy

A Deep Dive Into Attempted Exploitation of CVE-2023-33538
Published:
16 april 2026 om 22:00:13
Alert date:
16 april 2026 om 23:01:38
Source:
unit42.paloaltonetworks.com
Network Infrastructure, Mobile & IoT, Ransomware & Malware
CVE-2023-33538 is a command injection vulnerability affecting TP-Link routers that allows remote code execution. Unit 42 researchers analyzed exploitation attempts targeting this vulnerability in the wild. The attacks use payloads characteristic of Mirai botnet malware, indicating active exploitation by threat actors. The vulnerability represents a significant threat to network infrastructure as it affects widely deployed consumer and enterprise networking equipment. Successful exploitation allows attackers to gain control of affected devices and potentially incorporate them into botnets for further malicious activities.
Technical details
Mitigation steps:
Affected products:
TP-Link routers
Related links:
https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/
https://unit42.paloaltonetworks.com
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
