Back to News
Market Impact: 0.25

Cisco security flaw exploited to build botnet of thousands of devices

CSCO
Cybersecurity & Data PrivacyTechnology & Innovation
Cisco security flaw exploited to build botnet of thousands of devices

Cybersecurity researchers at Sekoia have identified a new botnet, ViciousTrap, exploiting a high-severity vulnerability (CVE-2023-20118) in older Cisco Small Business routers to compromise over 5,300 devices globally. The vulnerability, which Cisco will not patch due to the devices being past end-of-life, allows remote attackers to execute arbitrary commands and redirect network traffic. This follows a similar botnet, PolarEdge, discovered earlier this year using the same vulnerability to target a broader range of devices.

Analysis

Sekoia cybersecurity researchers have reported the emergence of a new botnet, "ViciousTrap," actively exploiting a high-severity vulnerability (CVE-2023-20118) in specific end-of-life Cisco Small Business routers. This vulnerability, located in the web-based management interface, permits authenticated remote attackers to execute arbitrary commands due to improper user input validation. Over 5,300 devices across 84 countries, with a significant concentration in Macau (850 devices), have been compromised and assimilated into this botnet, which redirects network traffic using a shell script named NetGhost. Cisco has stated it will not issue a patch for these affected routers—models RV016, RV042, RV042G, RV082, RV320, and RV325—as they have surpassed their end-of-life support date. This incident follows a February 2025 alert concerning the "PolarEdge" botnet, which exploited the same vulnerability impacting approximately 2,000 devices. The ViciousTrap attacks, originating from a single IP address since March 2025, are attributed by Sekoia to potentially Chinese threat actors who repurposed a web shell from the PolarEdge campaign. The associated per-ticker sentiment for Cisco (CSCO) is moderately negative at -0.55, though the broader market impact score remains low at 0.25, suggesting the direct financial repercussions for Cisco from these EOL products are perceived as limited.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.55

Ticker Sentiment

CSCO-0.55

Key Decisions for Investors

  • For investors in Cisco (CSCO), while the direct financial impact from these specific end-of-life routers is likely minimal, the negative sentiment and the unpatched status of a known vulnerability highlight a potential minor reputational consideration; monitor for any patterns in managing security for aging products or shifts in customer perception.
  • The proliferation of botnets exploiting known vulnerabilities in EOL hardware underscores the persistent demand for advanced cybersecurity solutions, potentially benefiting companies specializing in network security, threat intelligence, and legacy system protection.
  • This event serves as a reminder of the inherent risks associated with end-of-life hardware for enterprises, emphasizing the importance of diligent lifecycle management and security assessments for infrastructure components.