www.securityweek.com 4/22/2026, 12:08:38 PM · via preferred

Mirai botnet exploits old D Link routers via CVE-2025-29635 flaw

Mirai Botnet Hijacks Old DLink Routers Via CVE-2025-29635

A Mirai botnet is actively exploiting a command injection flaw, tracked as CVE-2025-29635, in discontinued D-Link DIR-823X series routers, according to Akamai. The vulnerability allows attackers to inject commands because an attacker-controlled value is copied without proper validation, affecting firmware versions 240126 and 24082. Exploitation began about…

First seen 2026-04-22T12:08:38.210Z · Last seen 2026-04-22T18:01:52.652Z

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A Mirai botnet is targeting discontinued D-Link routers impacted by a command injection vulnerability disclosed a year ago, according to Akamai. Tracked as CVE-2025-29635, the security defect exists because an attacker-controllable function value is copied without validation and can be exploited through crafted POST requests. The observed exploitation attempts target the same code and trigger the same system call as a PoC exploit published last year on GitHub, which has since been removed.

As part of the observed execution path, a shell script is loaded to download and run a payload that exhibits several Mirai characteristics, including XOR encoding, a hardcoded console execution string, and a hardcoded downloader IP. The issue affects D-Link DIR-823X series router firmware versions 240126 and 24082; these devices were discontinued last year and no longer receive software updates from the vendor, with D-Link stressing that the product should be retired. Akamai notes that the threat actors have also been observed targeting TP-Link and ZTE router vulnerabilities.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline