Skip to content

CVE-2023-50224

CVE

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
March 25, 2026
Last Seen
May 22, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

The FBI and partners disrupted a covert network of compromised TP-Link and MikroTik routers exploited by the Russian GRU (APT28) to steal Outlook credentials. This operation, known as Operation Masquerade, revealed that over 5,000 consumer devices across 23 states were affected, with the attack leve...

Russian cyber group APT28, also known as Fancy Bear, has been exploiting vulnerabilities in TP-Link and MikroTik routers to conduct large-scale DNS hijacking operations. This campaign, which has affected over 18,000 devices across 120 countries, allows attackers to intercept internet traffic and ste...

TP-Link has patched multiple critical vulnerabilities in its Archer NX router series, specifically affecting models NX200, NX210, NX500, and NX600. The most severe flaw, CVE-2025-15517, allows unauthenticated attackers to bypass authentication and upload malicious firmware. Other vulnerabilities, CV...

Public Exploits

Checking GitHub for proof-of-concept code…