• News/
  • https://www.bleepingcomputer.com/news/security/rondodox-botnet-targets-56-n-day-flaws-in-worldwide-attacks/

RondoDox botnet targets 56 n-day flaws in worldwide attacks

BleepingComputer
·
Bill Toulas
·
Published Oct 9, 2025
·
Updated

A new large-scale botnet called RondoDox is targeting 56 vulnerabilities in more than 30 distinct devices, including flaws first disclosed during Pwn2Own hacking competitions. The attacker focuses on a wide range of exposed devices, including DVRs, NVRs, CCTV systems, and web servers and have been active since June. The RondoDox botnet leverages what Trend Micro researchers call an “exploit shotgun” strategy, where numerous exploits are used simultaneously to maximize the infections, even if the activity is very noisy. Since FortiGuard Labs discovered RondoDox, the botnet appears to have expanded the list of exploited vulnerabilities, which included CVE-2024-3721 and CVE-2024-12856. In a report today, Trend Micro says that RondoDox exploits CVE-2023-1389, a flaw in the TP-Link Archer AX21 Wi-Fi router that was originally demonstrated at Pwn2Own Toronto 2022. Pwn2Own is a hacking competition organized twice a year by Trend Micro's Zero Day Initiative (ZDI), where white-hat teams demonstrate exploits for zero-day vulnerabilities in widely used products. The security researchers note that the botnet developer pay close attention to exploits demonstrated during Pwn2Own events, and move quickly to weaponize them, as Mirai did with CVE-2023-1389 in 2023. Below is a list of post-2023 n-day flaws RondoDox includes in its arsenal: Older flaws, especially in devices that reached end of life, are a significant risk as they are more likely to remain unpatched. More recent ones in suppor...

Read full article

Affected Software

1 affected component
TP-Link Archer AX21
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the primary focus of the RondoDox botnet attacks?

The RondoDox botnet targets 56 vulnerabilities in over 30 different devices.

2

What types of devices are affected by the RondoDox attacks?

The botnet targets a wide range of exposed devices, including models like the TP-Link Archer AX21.

3

What does 'n-day vulnerabilities' refer to in the context of this article?

N-day vulnerabilities refer to flaws that have already been disclosed and may be exploited if not patched.

4

Which hacking competition's flaws are being exploited by RondoDox?

The botnet exploits flaws first disclosed during the Pwn2Own hacking competitions.

5

What security implications are highlighted by the RondoDox botnet activity?

The widespread targeting of multiple vulnerabilities indicates a significant risk to various networked devices worldwide.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203