BadCandy exploitation of Cisco IOS XE routers in Australia
Case score 70
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 70
- Main story score
- 65
- Related evidence lift
- +5 / 20
- Contributing updates
- 2
- Context updates
- 0
- Vulnerability Anchors the case on the Cisco IOS XE web UI flaw and the takeover path used to plant BadCandy. main
- Exploitation Wave Adds the Australia exploitation-wave reporting, compromise counts, and remediation guidance for the same CVE-2023-20198 activity. contributes
- Exploitation Wave Reinforces the same BadCandy reinfection pattern on exposed Cisco IOS XE systems in Australia. contributes
Overview
Latest development Open development history ASD warns of ongoing BADCANDY attacks on unpatched Cisco IOS XE devices in Australia The Australian Signals Directorate warned that ongoing cyber attacks in Australia are targeting unpatched Cisco IOS XE devices with BADCANDY, a low-equity Lua-based web shell tied to exploitation of CVE-2023-20198. ASD said the vulnerability has been actively exploited since late 2023, variations of BADCANDY have been detected since October 2023, and as many as 400 devices in Australia may have been compromised since July 2025, including 150 in October. The agency urged operators to apply patches, limit public exposure of the web user interface, and review privileged accounts, unknown tunnel interfaces, and TACACS+ AAA command accounting logs.
-
Australian government warns of ongoing BadCandy infections on unpatched Cisco IOS XE routers
The Australian Signals Directorate is notifying victims after detecting ongoing exploitation of CVE-2023-20198 against unpatched Cisco IOS XE devices in Australia, where the Lua-based BadCandy webshell can let remote unauthenticated attackers create a local admin user through the web interface, gain root command execution, and re-introduce the implant after reboot if the web interface remains exposed. The agency says over 400 devices were potentially compromised since July 2025 and more than 150 were still compromised as at late October 2025, with internet service providers asked to contact victims whose owners cannot be identified and administrators directed to patch and harden affected devices.