Executive Summary
In mid-2025, the RondoDox botnet emerged as a powerful threat targeting IoT and network devices by exploiting 56 known (n-day) vulnerabilities across over 30 device types, including routers, NVRs, DVRs, and CCTV systems. The operators, closely monitoring vulnerability disclosures—such as those revealed at Pwn2Own events—rapidly weaponized publicly disclosed exploits, including CVE-2023-1389 and CVE-2024-12856, using a high-volume "exploit shotgun" methodology to maximize infections. With operations observed since June 2025, the campaign affected both end-of-life and actively supported products, resulting in a widespread compromise of infrastructure, particularly among organizations and consumers with unpatched devices.
This attack underscores a growing trend of mass exploitation of n-day vulnerabilities in IoT ecosystems, reflecting increasing automation and sophistication among botnet operators. The pace at which attackers operationalize new exploits demands faster patching, improved segmentation, and heightened baseline security practices across networked environments.
Why This Matters Now
The RondoDox campaign highlights the urgent risk of unpatched IoT and edge devices as threat actors rapidly exploit newly disclosed vulnerabilities at scale. With attackers leveraging a broad arsenal of n-day exploits, organizations face heightened exposure unless they accelerate patch management, strengthen segmentation, and replace unsupported equipment.
Attack Path Analysis
The RondoDox botnet initiated attacks by exploiting exposed n-day vulnerabilities in a broad range of internet-facing devices, compromising routers, DVRs, and cameras worldwide. Post-compromise, the malware established persistence and potentially escalated privileges to control targeted devices. The compromised hosts were then used to move laterally within flat or poorly segmented networks, infecting additional vulnerable systems. Once a foothold was maintained, infected devices communicated with external command and control servers using outbound connections to receive instructions. The attackers exfiltrated sensitive data or leveraged infected assets to propagate the botnet further, and ultimately, the impact included large-scale device hijacking, possible data exfiltration, degradation of network security posture, and disruptions across affected environments.
Kill Chain Progression
Initial Compromise
Description
Attackers mass-exploited unpatched n-day flaws (CVE-2023-1389, CVE-2024-3721, others) in internet-exposed IoT and network devices to gain initial remote code execution.
Related CVEs
CVE-2023-1389
CVSS 8.8A command injection vulnerability in the TP-Link Archer AX21 Wi-Fi router allows unauthenticated remote attackers to execute arbitrary commands.
Affected Products:
TP-Link Archer AX21 – Firmware versions prior to 1.1.4 Build 20230219
Exploit Status:
exploited in the wildCVE-2023-7304
CVSS 9.3A command injection vulnerability in the Ruijie RG-UAC Application Management Gateway via the 'nmc_sync.php' interface allows unauthenticated remote attackers to execute arbitrary commands.
Affected Products:
Ruijie RG-UAC Application Management Gateway – All versions prior to the latest patch
Exploit Status:
exploited in the wildCVE-2023-7311
CVSS 9.3A command injection vulnerability in the BYTEVALUE Intelligent Flow Control Router via the '/goform/webRead/open' endpoint allows unauthenticated remote attackers to execute arbitrary commands.
Affected Products:
BYTEVALUE Intelligent Flow Control Router – All versions prior to the latest patch
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Network Sniffing
Network Service Scanning
Command and Scripting Interpreter
Valid Accounts
Account Manipulation
Remote Services
System Services
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of System Components and Software
Control ID: 6.3.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
NIS2 Directive – Vulnerability Handling and Disclosure
Control ID: Article 21(2)(d)
CISA ZTMM 2.0 – Automated Asset Inventory and Patch Management
Control ID: Asset Management-2
DORA – ICT Risk Management Framework
Control ID: Article 8(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Critical exposure to RondoDox botnet exploiting network device vulnerabilities including routers, WiFi equipment, and communication infrastructure requiring immediate firmware updates and segmentation.
Security/Investigations
High-risk targeting of CCTV systems, DVRs, NVRs and surveillance equipment through 56 n-day exploits compromising physical security monitoring and investigation capabilities.
Information Technology/IT
Severe impact from botnet's exploit shotgun strategy targeting web servers, network infrastructure, and IoT devices requiring enhanced threat detection and anomaly response.
Health Care / Life Sciences
Significant compliance risk as botnet targets medical device networks and IoT systems, potentially violating HIPAA requirements for data protection and access controls.
Sources
- RondoDox botnet targets 56 n-day flaws in worldwide attackshttps://www.bleepingcomputer.com/news/security/rondodox-botnet-targets-56-n-day-flaws-in-worldwide-attacks/Verified
- CVE-2023-1389 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2023-1389Verified
- CVE-2023-7304 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2023-7304Verified
- CVE-2023-7311 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2023-7311Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Zero Trust network segmentation, policy-driven egress controls, and real-time intrusion prevention would have greatly limited the botnet's ability to propagate, communicate externally, and persist. CNSF-aligned controls would have segmented vulnerable devices, detected exploitation and anomalous behavior, and constrained C2 or exfiltration traffic.
Control: Zero Trust Segmentation
Mitigation: Reduced external attack surface and minimized exposure of vulnerable devices.
Control: Threat Detection & Anomaly Response
Mitigation: Detected abnormal privilege changes or suspicious device behavior.
Control: East-West Traffic Security
Mitigation: Blocked malicious lateral movement across network segments.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented or detected unauthorized outbound beaconing to external hosts.
Control: Multicloud Visibility & Control
Mitigation: Allowed rapid identification and response to suspicious large-scale outbound data flows.
Limited attack blast radius and enabled automated mitigation at scale.
Impact at a Glance
Affected Business Functions
- Network Operations
- Surveillance Systems
- Web Services
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive surveillance footage and unauthorized access to network resources.
Recommended Actions
Key Takeaways & Next Steps
- • Segment and isolate internet-exposed IoT and legacy devices using Zero Trust network and microsegmentation controls.
- • Enforce egress filtering and policy-based outbound controls to block botnet C2 communications and data exfiltration.
- • Monitor for anomalies across internal and east-west flows using real-time visibility and baseline detection.
- • Rapidly apply firmware updates to all networked devices and retire unsupported/EoL hardware to reduce exploit surface.
- • Implement centralized, cloud-native security fabric for automated response and least privilege enforcement throughout the hybrid network.



