
CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492: Router Exploits Enable Persistent APT Access (July 2026)
CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492 — Router Vulnerabilities
These high-severity CVEs are actively exploited by the China-linked APT group UAT-7810 to compromise internet-facing networking devices. Attackers use these flaws to deploy the new LONGLEASH malware, enabling persistent access and advanced proxying for secondary threat actors. No CVSS scores have been published, but exploitation is confirmed in the wild.
Attack Vector
UAT-7810 targets unpatched routers using a combination of bespoke backdoors and exploits for CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492. The attackers deploy LONGLEASH, ShortLeash, and DOGLEASH malware variants, as well as the LEASHTEST ELF binary and JARLEASH Java-based backdoor. Compromised devices are enrolled into the Operational Relay Box (ORB) network, acting as proxies for further attacks. At least four new servers hosting DOGLEASH variations have been identified, indicating ongoing expansion.
Who Is at Risk
All organizations with internet-facing routers vulnerable to these CVEs are at risk, especially those in critical infrastructure sectors. Devices running outdated firmware or lacking recent security patches are prime targets. No specific vendors are named, but the campaign is active across the Asia-Pacific region and may expand globally.
Patch & Mitigate
- Patch: Apply vendor firmware updates addressing CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and CVE-2025-2492 immediately. Check vendor advisories for model-specific guidance.
- Workaround: Restrict management interfaces to trusted networks and disable remote administration if possible.
- Detect: Monitor for unusual outbound connections, presence of LONGLEASH, ShortLeash, DOGLEASH, LEASHTEST, or JARLEASH binaries, and unexpected proxy or relay traffic.
MITRE ATT&CK
- TA0011 — Command and Control: LONGLEASH establishes persistent C2 channels using compromised routers.
- TA0005 — Defense Evasion: Custom malware variants evade detection and maintain stealthy access.
- TA0007 — Discovery: Attackers enumerate network devices to identify further exploitation targets.
Source: https://thehackernews.com/2026/07/china-linked-uat-7810-expands-orb.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

