Botnet operators have targeted a critical command-injection flaw in BYTEVALUE Intelligent Flow Control Routers, tracked as CVE-2023-7311 with a CVSS v4.0 score of 9.3. Improper validation of the path parameter at /goform/webRead/open allows remote attackers to execute arbitrary shell commands without authentication or user interaction, potentially compromising the router and its management functions. The CVE record references publicly available exploits and reports that the RondoDox botnet campaign has targeted the vulnerability; VulnCheck also published a dedicated advisory.
Earlier SANS Internet Storm Center honeypot observations documented attempts against the same endpoint, then associated with BYTEVALUE routers but without an identified CVE or located patch. The payload attempted to delete files and download and execute bruh.sh from 192.3.152.183, which subsequently retrieved malware binaries for multiple processor architectures. An examined UPX-packed binary was identified by antivirus engines as a Mirai variant and contained strings referencing other router exploits. Those observations did not establish successful compromise of production routers. Organizations operating affected devices should restrict internet-facing management access, verify remediation options with the vendor, and investigate suspicious downloads or unexpected outbound traffic.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
VulnCheck published CVE-2023-7311 for unauthenticated command injection through the /goform/webRead/open path parameter in BYTEVALUE Intelligent Flow Control Routers. The record assigns a critical CVSS v4.0 score of 9.3, marks the vulnerability as known exploited, and references a public Nuclei exploit template.
VulnCheck reported observing the RondoDox botnet campaign targeting the BYTEVALUE router command-injection vulnerability. The source does not specify when the campaign activity occurred.
Johannes B. Ullrich analyzed a UPX-packed payload containing references to other router exploits and uploaded the previously unlisted sample to VirusTotal, where detections identified it as a Mirai variant. He could not identify a specific CVE or locate a patch for the suspected BYTEVALUE vulnerability.
Honeypots observed shell commands injected through the endpoint's path parameter to delete files and download and execute bruh.sh from 192.3.152.183. The script retrieves and launches binaries for multiple processor architectures; successful compromise of production routers was not confirmed.
SANS honeypot sensors detected requests targeting /goform/webRead/open before observing requests containing a command-injection payload.
A Chinese blog post associated the /goform/webRead/open endpoint with a vulnerability in BYTEVALUE routers. Ullrich later cited the post when investigating exploit attempts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcevulncheck.com
Open sourceisc.sans.edu
Open sourceisc.sans.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.