CVE-2023-33538Active Exploitation(tp-link / tl-wr740n)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch tp-link tl-wr740n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm .

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-07-07. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tl-wr740n
  • tl-wr740n_firmware
  • tl-wr841n
  • tl-wr841n_firmware

Threat summary

  • Active exploitation appears in 21 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 35 mentions across 10 observed days

What's happening

  • Active exploitation reported across 21 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • General: 12 classified signals
  • Peaked 6d ago at 9 mentions (2026-04-18); latest day: 1
  • 35 total mentions across 10 days

Affected systems

Vendors
Products
tl-wr740ntl-wr740n_firmwaretl-wr841ntl-wr841n_firmwaretl-wr940ntl-wr940n_firmware

6 versions affected across 6 products

Deep dive

Activity timeline35 mentions / 10d
02579Mentions · 2026-03-16: 1Mentions · 2026-04-16: 2Mentions · 2026-04-17: 6Mentions · 2026-04-18: 9Mentions · 2026-04-19: 1Mentions · 2026-04-20: 9Mentions · 2026-04-21: 3Mentions · 2026-04-23: 2Mentions · 2026-04-27: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-04-18: 1Exploit Tool / Code · 2026-04-18: 2Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 5Active Exploitation · 2026-04-18: 7Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-20: 4Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-04-27: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 2Technical Details · 2026-04-20: 4Technical Details · 2026-04-23: 103-1604-1604-1704-1804-1904-2004-2104-2304-2710-07
Signal classification3 categories
Active Exploitation
2161.8%
General
1235.3%
Exploit
12.9%
Referenced assets20 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-161
Active Exploitation1
2026-04-162
Active Exploitation1General1
2026-04-176
Active Exploitation5General1
2026-04-189
Active Exploitation7Exploit1General1
2026-04-191
Active Exploitation1
2026-04-209
Active Exploitation4General5
2026-04-213
General3
2026-04-232
Active Exploitation1General1
2026-04-271
Active Exploitation1
Full discourse20 posts
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Unit 42 notes that CVE-2023-33538 enables command injection on TP-Link routers and discusses exploitation attempts using Mirai-like payloads. https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/

    Post summary

    Unit 42 reports that CVE-2023-33538 enables command injection on TP‑Link routers and that Mirai‑like payloads are being used in active exploitation attempts.

    0511381.0K
    22.4K followersView on X
  • Mololuwa | Cybersecurity - (The God Complex)@cyber_rekk

    I dug into the complaints and the federal record There is actually a pretty substantial technical history behind this The biggest one is CVE-2023-50224. Russian GRU operators exploited vulnerable TP-Link routers, and the NSA/FBI say thousands of TP-Link routers were compromised. The attackers used the routers for DNS hijacking, redirecting victims' DNS requests through attacker-controlled infrastructure There are other examples too, CVE-2023-33538, a TP-Link command-injection vulnerability, was added to CISA's Known Exploited Vulnerabilities catalog because there was evidence it was being actively exploited And the Florida investigation didn't suddenly appear today. Florida's AG opened a consumer-protection investigation and subpoenaed TP-Link in December 2025, specifically asking about its security practices, software development, supply chain, corporate structure and handling of U.S. consumer data Then in April 2026, the FBI and NSA publicly said Russian military intelligence had been exploiting TP-Link routers to steal credentials and use compromised routers for DNS-hijacking operations longer post coming soon

    230104922
    23.3K followersView on X
  • Nicolas Krassas@Dinosn
    General

    A Deep Dive Into Attempted Exploitation of CVE-2023-33538 https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/

    Post summary

    The text references a detailed analysis of attempted exploitation of CVE-2023-33538 but provides no concrete evidence of PoC, exploit tools, active attacks, or mitigation measures.

    020921.3K
    157.6K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    TP-Link社Wi-Fiルータの脆弱性CVE-2023-33538を狙う攻撃の観測について。パロアルトネットワークス社報告。 https://origin-unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/

    Post summary

    A Palo Alto Networks unit42 report confirms that attacks exploiting the TP‑Link Wi‑Fi router vulnerability CVE‑2023‑33538 are actively occurring in the wild.

    00033807
    7.6K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    TP-Link社Wi-Fiルータの脆弱性CVE-2023-33538を狙う攻撃の観測について。パロアルトネットワークス社報告。 https://origin-unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/

    Post summary

    Observations of attacks exploiting TP‑Link router CVE‑2023‑33538 were reported by Palo Alto Networks.

    00031832
    7.6K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    General

    CVE-2023-33538 under attack for a year, but exploitation still unsuccessful https://securityaffairs.com/191040/hacking/cve-2023-33538-under-attack-for-a-year-but-exploitation-still-unsuccessful.html #securityaffairs #hacking

    Post summary

    A brief post notes that CVE-2023-33538 has been targeted for a year, but no exploitation, patch, PoC, or technical details are provided.

    11010232
    37.6K followersView on X
  • Misbar | مسبار@MisbarSec
    General

    📌 استهداف أجهزة TP-Link ببرمجيات خبيثة Mirai في محاولات استغلال CVE-2023-33538 يقوم المخترقون باستهداف أجهزة TP-Link باستخدام برمجيات خبيثة Mirai في محاولات استغلال CVE-2023-33538. استغلال هذه الثغرة يسمح للمخترقين بتثبيت برمجيات خبيثة على الأجهزة الضعيفة. تأثرت أنظمة التوجيه اللاسلكية TP-Link التي وصلت إلى نهاية عمرها الافتراضي بهذه الهجمات. 🔗 للمزيد: https://cybersecuritynews.com/hackers-target-tp-link-routers/

    Post summary

    The post reports attackers using Mirai malware to target TP‑Link routers via CVE‑2023‑33538, but offers no PoC, exploit details, or patch information.

    00030626
    268 followersView on X
  • Cybercrimeinfo (ccinfo)@CCINLCybercrime
    Active Exploitation

    🚨 Cyber Dreigingsradar 17 april 2026 Dreigingsniveau VERHOOGD (72/100) • 35 nieuwe incidenten in NL/BE (24u) • CVE-2025-43300 (CVSS 10.0) actief misbruikt • CVE-2023-33538 aanvallen op TP-Link routers https://www.digiweerbaar.nl/cyber-dreigingsradar #cyberdreiging #dreigingsradar #cybersecurity

    Post summary

    The report highlights that CVE-2025-43300, rated at CVSS 10.0, is actively exploited, and it also mentions ongoing attacks on TP‑Link routers via CVE-2023-33538, indicating an elevated threat level.

    02010597
    3.1K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    TP-Link Router の脆弱性 CVE-2023-33538:EOL 狙いの Mirai 亜種配布を検知 https://iototsecnews.jp/2026/04/17/tp-link-routers-hit-by-mirai-in-cve-2023-33538-attacks/ TP-Link の古いルーターには、Wi-Fi設定 (SSID) を受け取るプログラムにおける不十分なチェックという、古い脆弱性 CVE-2023-33538 が存在します。この脆弱性の悪用により、設定画面で入力された文字列がシステム・コマンドとして実行される、コマンド・インジェクション攻撃が成立します。この欠陥を突く攻撃者は、ルーターを Mirai ボットネットの亜種に感染させ、DDoS 攻撃の踏み台にしようとしています。現在観測されている攻撃には手順のミスがありますが、正しい手順での攻撃が実行されると、パスワードが初期設定 (admin:admin) の状態の古いルーターは簡単に乗っ取られてしまいます。ご利用のチームは、ご注意ください。 #CVE202333538 #EOL #Exploit #Mirai #TPLink #Vulnerability

    Post summary

    The post reports ongoing Mirai‑variant attacks exploiting CVE‑2023‑33538 through command injection on legacy TP‑Link routers, noting ease of takeover with default admin credentials but provides no PoC or patch information.

    02000244
    486 followersView on X
  • Chris Short@ChrisShort
    General

    TP-Link router owners beware | A Deep Dive Into Attempted Exploitation of CVE-2023-33538 #devopsish https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/

    Post summary

    The tweet alerts TP‑Link router users to an attempt to exploit CVE-2023‑33538, directing readers to a Unit42 article for further analysis.

    00011234
    19.1K followersView on X
  • DFIR Radar@DFIR_Radar
    General

    Year-long exploitation attempts against CVE-2023-33538 (CVSS 8.8) in TP-Link routers fail due to flawed attack code targeting wrong parameters and missing authentication. #DFIR_Radar https://t.co/sUz9mSQOfy

    Post summary

    The tweet reports that year‑long attempts to exploit CVE-2023-33538 on TP‑Link routers have failed due to flawed attack code, with no PoC, active exploitation, or patch referenced.

    10010150
    1.3K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 TP-Link router flaw (CVE-2023-33538) targeted in active attacks Command injection attempts → Mirai-like malware delivery → botnet propagation attempts (unsuccessful due to flawed exploits & device limits) 💡 Lesson: Not every CVE = real-world compromise. Poor exploit quality + environment constraints can break attacks ⚠️ Action: Update firmware, change default credentials, restrict remote access & monitor unusual router traffic https://securityaffairs.com/191040/hacking/cve-2023-33538-under-attack-for-a-year-but-exploitation-still-unsuccessful.html

    Post summary

    CVE‑2023‑33538 is being targeted in active command‑injection attempts, though exploits remain largely unsuccessful; prompt firmware updates and credential changes are recommended.

    01001172
    7.6K followersView on X
  • Joseph k@KlinkWow769
    General

    Hackers have targeted CVE-2023-33538 flaw in old TP-Link routers for a year, but no successful exploitation has been seen so far. #CyberSecurity https://t.co/OIH2zvgAWi

    Post summary

    The tweet notes a year of hacker interest in CVE‑2023‑33538 on TP‑Link routers but reports no observed exploitation and provides no technical or remedial details.

    1001063
    11 followersView on X
  • Asher Davila@Asher_Davila
    Active Exploitation

    Almost a year ago, we investigated active exploitation of CVE-2023-33538. What looked simple wasn’t. The real risk came from routers using default credentials, still widespread across #IoT. https://origin-unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/

    Post summary

    The post confirms that CVE-2023-33538 is being actively exploited, particularly targeting IoT routers with default credentials; no PoC, patch, or technical details are provided.

    0000183
    1.2K followersView on X
  • hackplayers@hackplayers
    Active Exploitation

    CVE-2023-33538 under attack for a year, but exploitation still unsuccessful https://securityaffairs.com/191040/hacking/cve-2023-33538-under-attack-for-a-year-but-exploitation-still-unsuccessful.html

    Post summary

    The CVE has been the target of exploitation attempts for a year, but no successful exploitation has been reported.

    00010302
    54.9K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    General

    CVE-2023-33538 under attack for a year, but exploitation still unsuccessful https://securityaffairs.com/191040/hacking/cve-2023-33538-under-attack-for-a-year-but-exploitation-still-unsuccessful.html #securityaffairs #hacking @PaloAltoNtwks

    Post summary

    The tweet references CVE-2023-33538, noting it has been targeted for a year but exploitation remains unsuccessful, with no PoC, exploit tool, patch, or technical details provided.

    01000219
    37.6K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    BREAKING: Hackers hit end-of-life TP-Link TL-WR940N, TL-WR740N, TL-WR841N routers via CVE-2023-33538, attempting Mirai-style botnet installs on devices using default credentials. https://threatcluster.io/cluster/active-exploitation-of-tp-link-routers-with-cve-2023-33538-l-bc1a8793

    Post summary

    The tweet reports that hackers are actively exploiting end-of-life TP‑Link routers via CVE‑2023‑33538, deploying Mirai‑style botnet installs using default credentials. No PoC, exploit tools, or patches are detailed.

    01000104
    155 followersView on X
  • 迪鹿DeluCat💖@DeluCatOfficial
    Active Exploitation

    這張是我目前手頭效能最好的﹐ 在猶豫要不要繼續使用 😰 所以去爬了些相關資料...... 看到是TP-Link的路由器易被駭客當跳板 https://www.secpod.com/blog/cisa-issues-warning-on-active-exploitation-of-tp-link-vulnerability-cve-2023-33538/ 被駭的是韌體已停更的舊型號路由器﹐被駭客鑽漏洞輸入指令控制。 目前看到的說法是﹐TP-Link路由器因便宜、市占率高﹐ 加上家用路由器大家通常不會去換﹐ 舊型號停更後大家還是繼續用﹐就被駭客鎖定了🤔 近期ASUS的舊型號路由器﹐也有被大堆模攻擊的災情﹐這是前幾天的新聞 https://www.itpro.com/security/thousands-of-asus-routers-are-being-used-to-fuel-a-massive-cyber-crime-spree?utm_source=chatgpt.com 但我目前沒有看到TP-Link網卡被駭的災情資料

    Post summary

    The post confirms that TP‑Link routers are being actively exploited via CVE‑2023‑33538, with attackers gaining command over older firmware models; no PoC, exploit code, patch, or debunking information is included.

    10000291
    26.8K followersView on X
  • twelvesec@twelvesec
    General

    #Hackers have been trying for over a year to exploit a #serious flaw (CVE-2023-33538) in outdated TP-Link routers, but so far without success. #CyberSecurity #InfoSec https://buff.ly/4OzJeCz https://t.co/cpmrytvonf

    Post summary

    The tweet notes that hackers have attempted for over a year to exploit CVE‑2023‑33538 in older TP‑Link routers, but have not succeeded.

    00000124
    1.5K followersView on X
  • Eyal Estrin ☁️@eyalestrin
    General

    Hackers Fail to Exploit Flaw in Discontinued TP-Link Routers (CVE-2023-33538) http://dlvr.it/TS8DxL #security #cybersecurity

    Post summary

    The tweet reports that hackers were unable to exploit CVE-2023-33538 in discontinued TP‑Link routers, but provides no further technical or remediation details.

    0000062
    2.0K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktl-wr740n1.0--
HWtp-linktl-wr740n2.0--
OStp-linktl-wr740n_firmware---
HWtp-linktl-wr841n10.0--
HWtp-linktl-wr841n8.0--
OStp-linktl-wr841n_firmware---
HWtp-linktl-wr940n2.0--
HWtp-linktl-wr940n4.0--
OStp-linktl-wr940n_firmware---

Explore more