A threat actor using the alias Anarchy reportedly assembled a botnet of roughly 18,000 compromised Huawei HG532 routers in a single day by exploiting CVE-2017-17215, a remote command execution flaw that had already been abused by Mirai-derived malware and Satori variants. The campaign highlighted how long-known weaknesses in internet-facing SOHO and IoT devices continue to provide attackers with a large pool of systems for botnet growth and potential DDoS or other criminal activity.
Public exploit details for CVE-2017-17215 showed that attackers could send a crafted SOAP request to the router's UPnP WANPPPConnection service on port 37215 and inject shell commands through the NewStatusURL field of the Upgrade action, using the default credentials dslf-config/admin. Reporting also indicated that the actor planned to expand operations by targeting CVE-2014-8361 in Realtek-based routers via port 52869, suggesting broader efforts to scale router-based botnet infections across poorly secured edge devices.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Exploit-DB published a verified proof-of-concept for arbitrary command execution on Huawei HG532 routers, identified as CVE-2017-17215. The entry showed how a crafted SOAP request to the router's WANPPPConnection service could execute shell commands remotely.
Huawei published a security notice confirming the existence of CVE-2017-17215, a remote code execution flaw affecting HG532 devices, after receiving the report from Check Point researcher Muhammad Mukatren on November 27, 2017. The company advised mitigations, noted IPS signature updates, and said fix versions were provided for non-End of Service products.
According to researcher Ankit Anubhav, Anarchy said he also planned to target CVE-2014-8361 in Realtek routers, exploitable via port 52869. This marked an intended expansion beyond Huawei HG532 devices.
Threat actor 'Anarchy' reportedly assembled a botnet of about 18,000 compromised devices in a single day by exploiting Huawei HG532 routers via CVE-2017-17215. The actor also shared a list of infected victim IP addresses with researcher Ankit Anubhav, who did not publish it.
A July 19 blog post cited by later reporting noted an increase in the number of compromised Huawei routers. This indicated active exploitation of CVE-2017-17215 in the wild before broader coverage of the botnet's scale.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcescmagazine.com
Open sourceexploit-db.com
Open sourcehuawei.com
Open sourcehuawei.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.