RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks

Researchers studying cybersecurity are drawing attention to a virus campaign that uses security holes in Four-Faith routers and TBK DVRs to enlist the devices in a brand-new botnet known as RondoDox.

The vulnerabilities in question include CVE-2024-12856, an operating system (OS) command injection flaw that affects Four-Faith router models F3x24 and F3x36, and CVE-2024-3721, a medium-severity command injection vulnerability that affects TBK DVR-4104 and DVR-4216 DVRs.

Many of these devices are placed in crucial locations, such as small offices, warehouses, and retail storefronts, where they sometimes remain unattended for years. They are therefore perfect targets because they are simple to exploit, difficult to find, and typically accessible to the internet directly due to out-of-date firmware or improperly set ports.

Notably, in recent months, threat actors have frequently used these three security flaws as weapons read more about RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *