Exploited Bug Bypasses Authentication On Numerous Routers

August 9, 2021

Tenable discovered a vulnerability on April 26 that is actively exploited by threat actors and is tracked as CVE-2021-20090.

The vulnerability affects home routers running Arcadyan firmware, which in turn paves the way for attackers to use malicious payloads from the Mirai botnet.

The vulnerable devices include dozens of router models from multiple providers and ISPs, including Asus, British Telecom, Deutsche Telekom, Orange, O2 (Telefonica), Verizon, Vodafone, Telstra and Telus.

The vulnerability found in the web interfaces of routers with Arcadyan firmware provides unauthenticated remote attackers with access to authentication bypass. Millions of routers are reportedly vulnerable to attack depending on how many router models and vendors are already affected by the bug.

The latest attacks were discovered by researchers from Juniper Threat Labs.

While Juniper Threat Labs “identified some attack patterns that attempt to exploit this vulnerability in the wild coming from an IP address located in Wuhan, Hubei province, China,” the report showed that threat actors actively exploiting the vulnerability could do so with malicious tools similar to those used in a Mirai campaign against IoT and network security using a Mirai botnet variant.

For more information, read the original story in Bleeping Computer.

Top Stories

Related Articles

March 30, 2026 Google has expanded its “Results about you” tool, allowing users to remove highly sensitive personal data, including more...

March 27, 2026 Microsoft is updating GitHub Copilot to train on real-world developer interactions, expanding beyond public code datasets to more...

March 23, 2026 David Shipley, co-host of Cybersecurity today is covering RSAC for Tech Newsday and Cybersecurity Today.  SAN FRANCISCO more...

March 23, 2026 The U.S. Federal Communications Commission has banned the import of all new foreign-made consumer routers following a more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn