TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Scanning for TP-Link Wifi Router Vulnerability Increases by 100%

2024-06-21 · Read original ↗

ATT&CK techniques detected

4 predictions
T1588.006Vulnerabilities
69%
“products which may not have patched their own copies. in the last 12 months, it peaked in july 2023, but it looked like scans were starting to fall off to a low and steady level until this month. may vulnerabilities by the numbers figure 1 shows may attack traffic for the top ten…”
T1595.002Vulnerability Scanning
59%
“( unmanaged ltd ). running these analyses again, we find that the situation has changed. now, the majority of the scanning ( 39 % ) is instead coming from as206264. as49870 is entirely absent. this indicates two things. network providers can and do work to limit scanning activity…”
T1584.005Botnet
59%
“twelve months. note the huge increase in scanning for cve - 2023 - 1389. long term trends figure 3 shows traffic for the top 19 cves by all - time traffic, followed by a monthly average of the remaining cves. this once again shows the dramatic increase in cve - 2023 - 1389, as we…”
T1588.006Vulnerabilities
33%
“( unmanaged ltd ). running these analyses again, we find that the situation has changed. now, the majority of the scanning ( 39 % ) is instead coming from as206264. as49870 is entirely absent. this indicates two things. network providers can and do work to limit scanning activity…”

Summary

The TP-Link Archer AX21 Wifi Router vulnerability CVE-2023-1389 experiences massive targeting along with a rather old critical RCE in PHPUnit.