RondoDox MAC-field command injection via /goform/set_LimitClient_cfg (CVE-2023-26801)
Detects exploitation attempts against LB-LINK routers via parameter injection in the 'set_LimitClient_cfg' endpoint (CVE-2023-26801) and subsequent command-and-control behavior, including outbound connections to known RondoDox staging IPs and DNS queries for associated malicious domains.
Microsoft Sentinel (KQL)

