The Mirai malware botnet is actively exploiting a vulnerability in TP-Link's Archer A21 (AX1800) WiFi router, identified as CVE-2023-1389, to integrate devices into DDoS (distributed denial of service) swarms.
Researchers first abused the flaw during the Pwn2Own Toronto hacking event in December 2020, where two different hacking groups compromised the device using different pathways (LAN and WAN interface access).
The flaw was disclosed to TP-Link in January 2023, while TP-Link released a fix last month in a new firmware update.
The exploitation attempts were detected by the Zero Day Initiative (ZDI) since last week, initially focused on Eastern Europe and spreading around the world.
See also: APT 'Tomiris' uses Turla malware, confusing researchers

Exploited by the Mirai botnet
The CVE-2023-1389 vulnerability is a high severity (CVSS v3: 8.8) unauthorized command injection bug in the Locale API of the web management interface of the TP-Link Archer AX21 router.
The source of the issue is a lack of input sanitization in the local language API that manages the router's language settings, which does not validate or filter what it receives. This allows remote attackers to input commands that should be executed on the device.
Hackers can exploit the flaw by sending a specially crafted request to the router that contains a command payload as part of the “country” parameter, followed by a second request that triggers the execution of the command.
The first signs of exploitation became apparent on April 11, 2023, and malicious activity is now being detected globally.

ZDI reports that a new version of the Mirai malware botnet is now exploiting the vulnerability to gain access to the device, downloading the appropriate binary payload for the router's architecture in order to recruit it into its botnet.
This particular version of Mirai focuses on launching DDoS attacks and its characteristics show that it mainly focuses on game servers, having the ability to launch attacks against the Valve Source Engine (VSE).

Another interesting aspect of this new malware variant is that it can mimic legitimate network traffic, making it harder for DDoS mitigation solutions to distinguish between malicious and legitimate traffic and effectively drop unwanted traffic.

See also: VirusTotal Code Insight: New AI-based malware analysis tool
TP-Link fix
TP-Link first attempted to address the issue on February 24, 2023, but the fix was incomplete and did not prevent the exploitation.
Finally, the networking equipment manufacturer released a firmware update that addressed the CVE-2023-1389 vulnerability on March 14, 2023, with version 1.1.4 Build 20230219.
See also: Intel CPUs vulnerable to new side-channel attack
Owners of the Archer AX21 AX1800 dual-band WiFi 6 router can download the latest firmware update for their device's hardware version from this website.
Signs of an infected TP-Link router include overheating of the device, internet disconnections , unexplained changes to the device's network settings , and resetting of administrator passwords.
Information source: bleepingcomputer.com
