AX21 the Ballista botnet continued to exploit a vulnerability in the TP-Link Archer AX21 router.
AX21 the Ballista botnet continued to exploit a vulnerability in the TP-Link Archer AX21 router.
does anyone know anything about this?
In April 2025, the Ballista botnet continued to exploit a vulnerability in the TP-Link Archer AX21 router. Specifically, the CVE-2023-1389 flaw, a command injection vulnerability, allowed attackers to gain control of the device and potentially execute remote code. The botnet has been used to propagate various malware, including Mirai, Condi, and AndroxGh0st.
