CyberzSOC

Publication detail
← Back to advisories & guidance

People's Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations ↗ source

September 18, 2024 FBI Alert
Co-sealed by: CNMF, FBI

Summary

The actors may then use the botnet as a proxy to conceal their identities while deploying distributed denial of service (DDoS) attacks or compromising targeted U.S. networks. Integrity Technology Group (Integrity Tech), a PRC-based company, has controlled and managed a botnet active since mid-2021. The botnet has regularly maintained between tens to hundreds of thousands of compromised devices. As of June 2024, the botnet consisted of over 260,000 devices. Victim devices which are part of the botnet have been observed in North America, South America, Europe, Africa, While devices aged beyond their end-of-life dates are known to be more vulnerable to intrusion, many of the compromised devices in the Integrity Tech-controlled botnet are likely still supported by their respective vendors.

News Coverage

DateSourceArticle
2026-08-26 Kaspersky Securelist Exploits and vulnerabilities in Q2 2026 CVE-2023-46604
2026-06-24 Kaspersky Securelist StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader CVE-2021-36260

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2017-7876 10.0 Critical n/a n/a This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the is…
CVE-2021-28799 10.0 Critical QNAP Network Attached Storage (NAS) QNAP NAS running HBS 3 contains an improper authorization vulnerability which can allow remote attackers to log in to a device.
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2022-20707 10.0 Critical Cisco Cisco Small Business RV Series Router Firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Ex…
CVE-2023-22515 10.0 Critical Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence …
CVE-2023-22527 10.0 Critical Atlassian Confluence Data Center and Server Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.
CVE-2023-46604 10.0 Critical Apache ActiveMQ Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run sh…
CVE-2015-7450 9.8 Critical IBM WebSphere Application Server and Server Hypervisor Edition Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote …
CVE-2019-17621 9.8 Critical D-Link DIR-859 Router D-Link DIR-859 router contains a command execution vulnerability in the UPnP endpoint URL, /gena.cgi. Exploitation allows an unauthenticated remote a…
CVE-2019-7256 9.8 Critical Nice Linear eMerge E3-Series Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.
CVE-2020-15415 9.8 Critical DrayTek Multiple Vigor Routers DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allow…
CVE-2020-4450 9.8 Critical IBM WebSphere Application Server IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially-craft…
CVE-2020-8515 9.8 Critical DrayTek Multiple Vigor Routers DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
CVE-2021-20090 9.8 Critical Arcadyan Buffalo Firmware Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and acc…
CVE-2021-36260 9.8 Critical Hikvision Security cameras web server A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation.
CVE-2022-1388 9.8 Critical F5 BIG-IP F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of fil…
CVE-2022-26134 9.8 Critical Atlassian Confluence Server/Data Center Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remo…
CVE-2022-30525 9.8 Critical Zyxel Multiple Firewalls A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execut…
CVE-2022-31814 9.8 Critical n/a n/a pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host heade…
CVE-2022-40881 9.8 Critical n/a n/a SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
CVE-2023-23333 9.8 Critical n/a n/a There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions throu…
CVE-2023-25690 9.8 Critical Apache Software Foundation Apache HTTP Server Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affec…
CVE-2023-28771 9.8 Critical Zyxel Multiple Firewalls Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute…
CVE-2023-3368 9.8 Critical Chamilo Chamilo Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code…
CVE-2023-3519 9.8 Critical Citrix NetScaler ADC and NetScaler Gateway Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
CVE-2023-35885 9.8 Critical n/a n/a CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
CVE-2023-37582 9.8 Critical Apache Software Foundation Apache RocketMQ The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version …
CVE-2023-38035 9.8 Critical Ivanti Sentry Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authenticati…
CVE-2023-46747 9.8 Critical F5 BIG-IP Configuration Utility F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that m…
CVE-2024-29973 9.8 Critical Zyxel NAS326 firmware ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmware versions before V5.21(AAZF.…
CVE-2024-4577 9.8 Critical PHP Group PHP PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This v…
CVE-2020-35391 9.6 Critical n/a n/a Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct reques…
CVE-2024-21762 9.6 Critical Fortinet FortiOS Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially…
CVE-2022-42475 9.3 Critical Fortinet FortiOS Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker …
CVE-2023-27997 9.2 Critical Fortinet FortiOS and FortiProxy SSL-VPN Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to exe…
CVE-2024-5217 9.2 Critical ServiceNow Utah, Vancouver, and Washington DC Now Platform ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpr…
CVE-2023-30799 9.1 Critical MikroTik RouterOS MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attack…
CVE-2023-27524 8.9 High Apache Superset Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthoriz…
CVE-2023-36542 8.8 High Apache Software Foundation Apache NiFi Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an …
CVE-2023-43478 8.8 High Telstra Smart Modem Gen 2 (Arcadyan LH1000) fake_upload.cgi on the Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, allows unauthenticated attackers to upload firmware…
CVE-2023-50386 8.8 High Apache Software Foundation Apache Solr Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Co…
CVE-2024-29269 8.8 High n/a n/a An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.
CVE-2023-24229 7.8 High n/a n/a DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v…
CVE-2020-3452 7.5 High Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests proc…
CVE-2023-33510 7.5 High n/a n/a Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.
CVE-2023-35843 7.5 High n/a n/a NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the serve…
CVE-2019-11829 7.3 High Synology Calendar OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrar…
CVE-2023-35081 7.2 High Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file w…
CVE-2021-45511 6.8 Medium n/a n/a Certain NETGEAR devices are affected by authentication bypass. This affects AC2100 before 2021-08-27, AC2400 before 2021-08-27, AC2600 before 2021-08…
CVE-2022-3590 5.9 Medium WordPress WordPress WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and …
CVE-2023-47218 5.8 Medium QNAP Systems Inc. QTS An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow…
CVE-2023-4166 5.5 Medium Tongda OA A vulnerability has been found in Tongda OA and classified as critical. This vulnerability affects unknown code of the file general/system/seal_manag…
CVE-2021-1472 5.3 Medium Cisco Cisco Small Business RV Series Router Firmware Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbit…
CVE-2021-1473 5.3 Medium Cisco Cisco Small Business RV Series Router Firmware Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbit…
CVE-2023-36844 5.3 Medium Juniper Junos OS Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to c…
CVE-2020-3451 4.7 Medium Cisco Cisco Small Business RV Series Router Firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote atta…
CVE-2023-3852 4.7 Medium OpenRapid RapidCMS A vulnerability was found in OpenRapid RapidCMS up to 1.3.1. It has been declared as critical. This vulnerability affects unknown code of the file /a…
CVE-2018-18852 — n/a n/a Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of…
CVE-2019-12168 — n/a n/a Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administration > Commands) screen.
CVE-2019-19824 — n/a n/a On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/for…
CVE-2021-46422 — n/a n/a Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any auth…
CVE-2023-26469 — n/a n/a In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
CVE-2023-28365 — Ubiquiti Inc. UniFi Network application A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administra…
CVE-2023-34598 — n/a n/a Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation …
CVE-2023-34960 — n/a n/a A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via …
CVE-2023-38646 — n/a n/a Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the serv…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.