<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Router-Security on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/router-security/</link><description>Recent content in Router-Security on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 01 Jan 2026 15:17:00 +0100</lastBuildDate><atom:link href="https://hackingpassion.com/tags/router-security/index.xml" rel="self" type="application/rss+xml"/><item><title>RondoDox Botnet: 56 Exploits, Gaming Traffic Disguise, and Self-Defense Against Recovery</title><link>https://hackingpassion.com/rondodox-botnet-react2shell-exploit-shotgun/</link><pubDate>Thu, 01 Jan 2026 15:17:00 +0100</pubDate><guid>https://hackingpassion.com/rondodox-botnet-react2shell-exploit-shotgun/</guid><description>&lt;p>RondoDox added React2Shell to its arsenal. 90,000+ servers. 56 vulnerabilities. 30+ vendors. They call it the &amp;ldquo;exploit-shotgun&amp;rdquo; approach. Fire everything, see what hits. 😱&lt;/p>
&lt;p>Once inside, RondoDox doesn&amp;rsquo;t just sit there. It launches DDoS attacks. Mines Monero. Turns infected devices into proxies to hide other attacks. And it breaks the tools needed to fight back.&lt;/p>
&lt;p>The botnet has been running for 9 months. Three distinct phases. March to April 2025 was reconnaissance. April to June was daily probing of WordPress, Drupal, Struts2, and IoT devices. July onward became hourly automated attacks at scale.&lt;/p></description></item><item><title>Your Router Just Failed: ASUS &amp; TP-Link Critical Vulnerabilities (CVE-2025-59367)</title><link>https://hackingpassion.com/asus-tplink-authentication-bypass-cve-2025/</link><pubDate>Sun, 16 Nov 2025 13:11:54 +0100</pubDate><guid>https://hackingpassion.com/asus-tplink-authentication-bypass-cve-2025/</guid><description>&lt;p>Your router protects your home network from the internet. Or it&amp;rsquo;s supposed to. Two major vendors just proved it doesn&amp;rsquo;t. 😅&lt;/p>
&lt;p>ASUS: CVE-2025-59367 (CVSS 9.3)
TP-Link: CVE-2025-7850 + CVE-2025-7851 (CVSS 9.3 + 8.7)&lt;/p>
&lt;p>Both disclosed November 2025. Both critical. Both letting attackers walk right in.&lt;/p>
&lt;h2 id="asus-routers-no-password-required">ASUS routers: No password required.&lt;/h2>
&lt;p>The vulnerability affects ASUS DSL-AC51, DSL-N16, and DSL-AC750 routers. Authentication bypass.&lt;/p>
&lt;p>If your router&amp;rsquo;s management interface is exposed to the internet, an attacker can connect remotely without any credentials. No username. No password. Direct admin access.&lt;/p></description></item></channel></rss>