TP-Link Confirms Botnet Vulnerability on Older Routers, Confirms Update Secures Users

BossMac Suba
By
BossMac Suba
Boss Mac Suba is the driving force behind Back2Gaming.com, a leading authority in PC gaming hardware and video game reviews. With over a decade of experience...

Microsoft and security researchers have issued updated advisories on the botnet known as CovertNetwork-1658, more commonly referred to as the Quad 7 (7777) botnet. The campaign, primarily involving compromised Small Office/Home Office (SOHO) routers, has been linked to Chinese threat actors conducting large-scale password spray attacks against Microsoft 365 accounts.

Attack Methodology

Investigations by Sekoia.io confirmed that the botnet exploits known vulnerabilities in TP-Link devices, including the TL-WR841N router. Attackers chained two vulnerabilities to achieve remote code execution:

  • CVE-2023-50224 – An unauthenticated file disclosure vulnerability allowed attackers to retrieve credentials stored in /tmp/dropbear/dropbearpwd.

  • CVE-2025-9377 – A command injection flaw in the Parental Control page permitted remote code execution once valid credentials were obtained.

This exploit chain is only viable when users enable the router’s remote administration interface on the internet—a feature disabled by default in TP-Link firmware. TP-Link advises against exposing this interface to the internet.

Discovery Timeline

  • June–July 2022: Independent researchers Gi7w0rm and Dunstable Toblerone first documented unusual botnet activity later identified as Quad 7.

  • July 2024: Sekoia.io confirmed TP-Link devices were being leveraged in password spray attacks against Microsoft 365 accounts.

  • September 2024: Reports indicated the botnet had expanded to target routers and VPN appliances from other vendors, including Zyxel, Asus, D-Link, and Netgear.

  • October 2024: Microsoft published a report linking compromised TP-Link devices to credential theft incidents affecting its customers.

Impacted Devices

Two older TP-Link models have been confirmed as vulnerable:

  • TL-WR841N/ND(MS) 9.0 – Firmware 3.16.9 Build 150320 Rel.57500n

  • Archer C7(EU) 2.0 – Firmware 3.15.3 Build 180305 Rel.51282n

Both are End-of-Life (EOL) products, superseded by newer models. Firmware patches have nonetheless been issued to address the vulnerabilities.

Vendor and Industry Response

TP-Link has:

  • Released patched firmware for affected routers despite their EOL status.

  • Engaged security researchers to collect additional samples of botnet payloads and identify new indicators of compromise.

  • Continued to monitor Quad 7 and related threats with industry partners to ensure customer protection.

Microsoft noted that Quad 7-related intrusion activity declined following public disclosures but continues to pose a risk for unpatched and exposed devices.

Recommendations

Users are strongly advised to:

  • Update affected TP-Link routers with the latest firmware patches.

  • Avoid exposing router administration interfaces to the internet.

  • Replace EOL hardware with supported devices offering current security models.

The Quad 7 botnet demonstrates the long-term risks posed by outdated SOHO equipment, with attackers continuing to exploit neglected devices for large-scale credential theft campaigns.

Source :
TAGGED:
Share This Article
Follow:
Boss Mac Suba is the driving force behind Back2Gaming.com, a leading authority in PC gaming hardware and video game reviews. With over a decade of experience in IT and more in doing reviews for things he love since 2002 from Jpop albums, anime series, games in the early days of the internet.Now he combines in-depth technical expertise with a no-nonsense approach to deliver data-driven, insightful content.Favorite quote: My favorite animal is the scapegoat."If it's not worth writing, it's not worth reading!" My stance on AI-generated writing and content
2 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *