CVE-2024-3912Active Exploitation

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-10: 1Active Exploitation · 2026-03-10: 103-10
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows KadNap malware exploiting CVE-2024-3080 and CVE-2024-3912 to hijack over 14,000 Asus routers into a stealth botnet. Attackers use modified Kademlia DHT protocol to hide C2 infrastructure within peer-to-peer networks, evading traditional detection. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/kadnap-malware-2026-asus-routers-botnet

    Post summary

    KadNap malware is actively exploiting CVE‑2024‑3080 and CVE‑2024‑3912, hijacking more than 14,000 Asus routers to build a stealth botnet that uses a modified Kademlia DHT protocol for peer‑to‑peer C2.

    0000078
    1.9K followersView on X

Explore more