VPNfilter official statement

It was less than a month between the increased botnet http vuln (03/28) & the discovery of the winbox vuln (04/23)

Can someone confirm VPNfilter exclusively utilizing the http vuln ?

A post in the http vuln (03/28) thread: “Also via the winbox port … We think there is a circular second exploit that works in a similar way to this.”

  • It was repeatedly stated the winbox port was getting hit only to identify the device as MT.

I don’t have a ton of time for forum searches, but i believe there were a few winbox vuln posts floating around between the http & winbox discoveries. The timeline feels fuzzy.

  • Sorry about the edits