TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Enterprises Should Consider Replacing Employees’ Home TP-Link Routers

2025-03-06 · Read original ↗

ATT&CK techniques detected

9 predictions
T1190Exploit Public-Facing Application
97%
“s in the range > = 5. 0. 10, < 5. 6. 3 or > = 4. 8. 19, < 4. 8. 28 you might just want to go ahead and roll incident response at this point. cve - 2023 - 1389 : p - link archer ax21 remote code execution interest in exploiting the tp - link archer ax21 remote code execution vulne…”
T1190Exploit Public-Facing Application
90%
“the beginning of a downward trend here. figure 3. evolution of vulnerability targeting in the last twelve months. this view accentuates the recent changes in cve acvitity, of which cve - 2017 - 9841 is the most notable. conclusions most cves saw upward trends in volume this month…”
T1564.001Hidden Files and Directories
90%
“##dbb270e8d749231d4ab70183e1ba8f48e9e hide. arm6 d551083639c3666e48324d3c36fcb0a32f218c72640486c83398fbb11d39be86 hide. arm7 4b59237adae094b7664e1786d1c5fb8ccefe7c11e1aace594ad4bd01424e436b hide. m68k a453be076c54164bb747194916f9274ea3322b249202917fc2e7b397002d81ed hide. mips b99…”
T1564.001Hidden Files and Directories
88%
“view the virustotal analyses. url : ( defanged ) hxxp : / / 154. 18. 239. 232 this ip is in the netblock 154. 18. 239. 0 / 24 which is registered to cogent, and then to ultahost, a global hosting provider. this particular netblock is registered with an address of jurong, singapor…”
T1190Exploit Public-Facing Application
84%
“table 1 shows the breakdown. as we can see, single - stage requests for a cve typically make up 1 % of incoming requests, and some cves see no single - stage requests at all. this is most easily explained by the nature of the cve, only cves that can directly result in remote code…”
T1190Exploit Public-Facing Application
76%
“and on into corporate infrastructure. there are no reported cases of this happening to date, but you may still want to act proactively to ensure that your employee edge devices aren ’ t vulnerable. cve - 2024 - 3721 : tbk dvr remote code execution exploitation attempts of tbk dvr…”
T1564.001Hidden Files and Directories
54%
“##ba hide. mpsl bc1faf4cd3c411a1273cbd0114846f6ae9539715d3effe0a5b6e5b62db0b8bd5 hide. ppc 24f8e5c0ede64a232078d6584c75e8f3e35e810a9cbbdc6114e8c7bb76d5779a hide. sh4 415b0bc279ee6ef354e9620a22cbcccf087493cad137ebb9b4b1fccdd9e2e5cf hide. spc 9f1b42c2402117540177f5798ac9b6c072bd361…”
T1190Exploit Public-Facing Application
44%
“##e - 2017 - 9841, with a number of relatively unsophisticated attacks. this is likely due to the accessibility of php payloads for threat actors breaking into the scene. one actor has been using the same stager payloads in pastebin since 2021 [ link ( https : / / pastebin. com /…”
T1190Exploit Public-Facing Application
42%
“enterprises should consider replacing employees ’ home tp - link routers the sensor intel series is created in partnership with efflux, who maintains a globally distributed network of sensors from which we derive attack telemetry. additional insights and contributions provided by…”

Summary

An examination of CVE trends from February 2025 scanning data.