Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave ×2

BadCandy exploitation of Cisco IOS XE routers in Australia

Updated 01.11.2025 15:43
Case score 70
Members 3 First seen 31.10.2025 17:38 Latest activity 01.11.2025 15:43

Overview

Ongoing exploitation of **CVE-2023-20198** on **Cisco IOS XE** routers in Australia is letting operators plant the **BadCandy** webshell on exposed management interfaces. Cisco fixed the flaw in October 2023, but available evidence shows repeated compromise across 2024 and 2025 on systems that stayed reachable and unpatched. ASD says as many as **400 devices** may have been compromised since July 2025, with **more than 150** still compromised in late October 2025. Operators are being told to patch, harden the web UI, and review privileged accounts and command-accounting logs; rebooting alone does not remove the underlying exposure.
Latest development Open development history 1 earlier development ASD warns of ongoing BADCANDY attacks on unpatched Cisco IOS XE devices in Australia The Australian Signals Directorate warned that ongoing cyber attacks in Australia are targeting unpatched Cisco IOS XE devices with BADCANDY, a low-equity Lua-based web shell tied to exploitation of CVE-2023-20198. ASD said the vulnerability has been actively exploited since late 2023, variations of BADCANDY have been detected since October 2023, and as many as 400 devices in Australia may have been compromised since July 2025, including 150 in October. The agency urged operators to apply patches, limit public exposure of the web user interface, and review privileged accounts, unknown tunnel interfaces, and TACACS+ AAA command accounting logs.
  1. Earlier development

    Australian government warns of ongoing BadCandy infections on unpatched Cisco IOS XE routers

    The Australian Signals Directorate is notifying victims after detecting ongoing exploitation of CVE-2023-20198 against unpatched Cisco IOS XE devices in Australia, where the Lua-based BadCandy webshell can let remote unauthenticated attackers create a local admin user through the web interface, gain root command execution, and re-introduce the implant after reboot if the web interface remains exposed. The agency says over 400 devices were potentially compromised since July 2025 and more than 150 were still compromised as at late October 2025, with internet service providers asked to contact victims whose owners cannot be identified and administrators directed to patch and harden affected devices.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation
Threat context

Threat actor context

1 listed

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Vulnerability Cisco IOS XE remote admin flaw (CVE-2023-20198)
Updated 31.10.2025 17:38 Lead Contribution 65
Exploitation Active Exploitation Exploit Public Exploit CVSS 10.0 Critical Patch Patch Available

Ongoing exploitation of **CVE-2023-20198** keeps **Cisco IOS XE** devices exposed to **BadCandy** webshell planting, with confirmed compromise activity in **Australia** and cleanup-resistant reinfection. **Cisco** fixed the flaw in **October 2023**, but a **public exploit** and unpatched systems continue to drive abuse. The flaw lets remote unauthenticated attackers create a local admin user through the web interface and take over devices.

Exploitation Wave Cisco IOS XE BADCANDY exploitation wave (CVE-2023-20198)
Updated 01.11.2025 15:43 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 10.0 Critical Patch Patch Available

A sustained **BADCANDY** exploitation wave is targeting **unpatched Cisco IOS XE devices** in **Australia**, with repeated compromise linked to **CVE-2023-20198**. ASD estimated up to **400 devices** have been affected since **July 2025**, including **150 in October**. The activity has persisted since **October 2023** and continued through **2024 and 2025**. Exposed systems remain at risk of reinfection when they stay reachable and unpatched.

Exploitation Wave Cisco IOS XE BadCandy exploitation wave
Updated 31.10.2025 17:38 Scoring Support Contribution 2
Exploitation Active Exploitation Patch Patch Available

Ongoing **BadCandy** exploitation of **unpatched Cisco IOS XE devices** in **Australia** has left **over 150 devices** compromised and enabled repeat re-infection on previously alerted routers. The wave uses **CVE-2023-20198** to plant a **Lua-based webshell** that can grant **root-level command execution**. Cisco fixed the flaw in **October 2023**, but exposed systems remained vulnerable to renewed abuse through **2024 and 2025**.