• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

RondoDox Botnet Exploits Essential 2018 Vulnerability to Hijack ASUS Routers

Admin by Admin
May 24, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Cybersecurity agency VulnCheck’s newest analysis reveals that cybercriminals at the moment are focusing on outdated fashions of ASUS routers by exploiting a software program vulnerability from 2018, tracked as CVE-2018-5999. This can be a important unauthenticated configuration replace vulnerability with a CVSS rating of 9.8/10 that lets hackers change the settings of the router while not having a password.

The assaults had been found by the agency’s specialised system referred to as VulnCheck Canary Community. Additional probing revealed {that a} botnet (community of contaminated units operating the malware payload) named RondoDox botnet is behind these assaults, and people working it began exploiting the vulnerability on Could 17. Following these findings, the vulnerability has been added to the corporate’s Identified Exploited Vulnerabilities catalogue.

As per the analysis findings, shared with Hackread.com, the assault sample depends on a selected mechanism the place the attackers ship knowledge payloads to set the ateCommand_flag setting to 1. This modification prompts the router’s inside system interface, referred to as infosvr, to open up and settle for unauthorised configuration modifications from the skin.

VulnCheck’s Preliminary Entry group examined this methodology and efficiently used the vulnerability to vary the admin password of a router. What’s extra troubling is that regardless that code to abuse this vulnerability has been public since 2018, hackers had not used it in the actual world till now.

Jacob Baines, the Chief Expertise Officer at VulnCheck, defined the state of affairs in a LinkedIn put up, noting that “RondoDox is well-known for implementing a ton of exploits. Some analyses have tracked its CVE associations effectively into the 170s, so it’s not shocking or new that they’re utilizing older ones too.”

The issue is big as a result of these units are all over the place. ASUS routers are made in Taiwan and China and are extremely popular in properties. Baines added: “There are a ton of ASUS routers on-line, greater than 1 million, so it’s very conceivable that that is working for RondoDox.”

RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers
Credit score: Jacob Baines

RondoDox operators have been energetic since mid-2025, and largely assault techniques operating Linux software program, very similar to one other botnet operator referred to as Mirai. Nonetheless, RondoDox is targeted on a selected aim of beginning Denial of Service assaults. These assaults flood an internet site or system with an excessive amount of web visitors till it crashes.

In keeping with VulnCheck’s State of Exploitation 2026 report findings on edge gadget vulnerabilities, cybercriminals search for outdated tech that corporations don’t assist with software program updates anymore, technically referred to as end-of-life units.

VulnCheck discovered that 56 % of attacked web edge units in 2025 had been shopper routers. Additionally, 65 % of vulnerabilities utilized by botnets had been on unsupported tech. This makes it simple for scammers to take over residence web routers.

This warning follows latest protection by Hackread.com on one other RondoDox marketing campaign reported by CloudSEK, the place the botnet focused sensible cameras and web sites by exploiting a important Subsequent.js vulnerability referred to as React2Shell (CVE-2025-55182) to hijack servers with out a password.



Tags: ASUSBotnetCriticalExploitsHijackRondoDoxRoutersVulnerability
Admin

Admin

Next Post
Google I/O confirmed how the trail for AI-driven science is shifting

Google I/O confirmed how the trail for AI-driven science is shifting

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

3D Layered Textual content: The Fundamentals

3D Layered Textual content: Interactivity and Dynamicism

August 22, 2025
What time does the Fortnite Zero Hour Chapter Finale dwell occasion begin?

What time does the Fortnite Zero Hour Chapter Finale dwell occasion begin?

November 28, 2025

Trending.

Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

Researchers Uncover Crucial GitHub CVE-2026-3854 RCE Flaw Exploitable by way of Single Git Push

April 29, 2026
The Obtain: the tech reshaping IVF and the rise of balcony photo voltaic

The Obtain: the tech reshaping IVF and the rise of balcony photo voltaic

May 7, 2026
Undertaking possession (fairness and fairness)

Your work diary | Seth’s Weblog

May 6, 2026
From Shader Uniforms to Clip-Path Wipes: How GSAP Drives My Portfolio

From Shader Uniforms to Clip-Path Wipes: How GSAP Drives My Portfolio

May 7, 2026
Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

Google Introduces Simula: A Reasoning-First Framework for Producing Controllable, Scalable Artificial Datasets Throughout Specialised AI Domains

April 21, 2026

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

Google I/O confirmed how the trail for AI-driven science is shifting

Google I/O confirmed how the trail for AI-driven science is shifting

May 24, 2026
RondoDox Botnet Exploits Essential 2018 Vulnerability to Hijack ASUS Routers

RondoDox Botnet Exploits Essential 2018 Vulnerability to Hijack ASUS Routers

May 24, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved