Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mirai Botnet Exploits Vulnerability in Old D-Link Routers

Mirai Botnet Exploits Vulnerability in Old D-Link Routers

Posted on April 22, 2026 By CWS

Akamai has revealed that a Mirai botnet is actively exploiting a security flaw in discontinued D-Link routers. This vulnerability, identified as CVE-2025-29635, was first disclosed a year ago and remains a significant threat to users who have not retired these devices.

Understanding the Vulnerability

The vulnerability arises from a failure to validate an attacker-controlled function value, which can be manipulated through specially crafted POST requests. Akamai explains that the router processes data from the request body without verifying its source, allowing attackers to manipulate the command buffer.

This flaw is similar to a proof-of-concept exploit published on GitHub last year, which has since been removed. The attack involves loading a shell script to download and execute a payload with Mirai characteristics, such as XOR encoding and hardcoded execution strings.

Impact on D-Link Routers

The affected devices are part of the D-Link DIR-823X series, specifically firmware versions 240126 and 24082. These routers, having been discontinued last year, no longer receive software updates from D-Link, increasing the risk for users who continue to operate them.

In September, D-Link issued a warning advising users to retire these products to avoid potential security risks to connected devices. Despite this, exploitation attempts targeting these routers persist.

Wider Implications and Future Threats

Akamai notes that the attackers have also targeted vulnerabilities in TP-Link and ZTE routers, highlighting a broader threat across different brands. The ongoing Mirai malware campaigns leverage the original source code, which is easily accessible and often reused by both experienced and novice threat actors.

The low entry barrier and potential financial rewards continue to drive individuals towards engaging in botnet activities, posing ongoing challenges to cybersecurity efforts. Users are urged to upgrade to secure devices and remain vigilant against evolving threats.

As cyber threats continue to evolve, it is crucial for individuals and organizations to prioritize network security and take proactive measures to safeguard their systems.

Security Week News Tags:Akamai, botnet attacks, CVE-2025-29635, cyber threat, Cybersecurity, D-Link routers, discontinued products, IoT security, malware campaigns, Mirai botnet, network security, router firmware, TP-Link, Vulnerability, ZTE routers

Post navigation

Previous Post: Lotus Wiper Threatens Venezuela’s Energy Sector
Next Post: Global SIM Farm Network Reveals 87 Control Panels

Related Posts

Depthfirst Raises  Million for Vulnerability Management Depthfirst Raises $40 Million for Vulnerability Management Security Week News
Linx Security Secures M to Enhance Identity Governance Linx Security Secures $50M to Enhance Identity Governance Security Week News
Gambit Cyber Raises .4 Million in Seed Funding Gambit Cyber Raises $3.4 Million in Seed Funding Security Week News
Microsoft Bug Bounty Program Expanded to Third-Party Code Microsoft Bug Bounty Program Expanded to Third-Party Code Security Week News
Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack Hackers Target Popular Nx Build System in First AI-Weaponized Supply Chain Attack Security Week News
FBI Shares IoCs for Recent Salesforce Intrusion Campaigns FBI Shares IoCs for Recent Salesforce Intrusion Campaigns Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iranian Hackers Prepare for Potential Cyber Disruption
  • AI-Coded Applications: Security Challenges Uncovered
  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark