Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mirai Botnet Exploits Vulnerability in Old D-Link Routers

Mirai Botnet Exploits Vulnerability in Old D-Link Routers

Posted on April 22, 2026 By CWS

Akamai has revealed that a Mirai botnet is actively exploiting a security flaw in discontinued D-Link routers. This vulnerability, identified as CVE-2025-29635, was first disclosed a year ago and remains a significant threat to users who have not retired these devices.

Understanding the Vulnerability

The vulnerability arises from a failure to validate an attacker-controlled function value, which can be manipulated through specially crafted POST requests. Akamai explains that the router processes data from the request body without verifying its source, allowing attackers to manipulate the command buffer.

This flaw is similar to a proof-of-concept exploit published on GitHub last year, which has since been removed. The attack involves loading a shell script to download and execute a payload with Mirai characteristics, such as XOR encoding and hardcoded execution strings.

Impact on D-Link Routers

The affected devices are part of the D-Link DIR-823X series, specifically firmware versions 240126 and 24082. These routers, having been discontinued last year, no longer receive software updates from D-Link, increasing the risk for users who continue to operate them.

In September, D-Link issued a warning advising users to retire these products to avoid potential security risks to connected devices. Despite this, exploitation attempts targeting these routers persist.

Wider Implications and Future Threats

Akamai notes that the attackers have also targeted vulnerabilities in TP-Link and ZTE routers, highlighting a broader threat across different brands. The ongoing Mirai malware campaigns leverage the original source code, which is easily accessible and often reused by both experienced and novice threat actors.

The low entry barrier and potential financial rewards continue to drive individuals towards engaging in botnet activities, posing ongoing challenges to cybersecurity efforts. Users are urged to upgrade to secure devices and remain vigilant against evolving threats.

As cyber threats continue to evolve, it is crucial for individuals and organizations to prioritize network security and take proactive measures to safeguard their systems.

Security Week News Tags:Akamai, botnet attacks, CVE-2025-29635, cyber threat, Cybersecurity, D-Link routers, discontinued products, IoT security, malware campaigns, Mirai botnet, network security, router firmware, TP-Link, Vulnerability, ZTE routers

Post navigation

Previous Post: Lotus Wiper Threatens Venezuela’s Energy Sector
Next Post: Global SIM Farm Network Reveals 87 Control Panels

Related Posts

Scattered Spider Hacker Sentenced to Prison Scattered Spider Hacker Sentenced to Prison Security Week News
Microsoft Addresses 83 Security Vulnerabilities in March Update Microsoft Addresses 83 Security Vulnerabilities in March Update Security Week News
Why We Can’t Let AI Take the Wheel of Cyber Defense Why We Can’t Let AI Take the Wheel of Cyber Defense Security Week News
Endpoint Security Firm Remedio Raises  Million in First Funding Round Endpoint Security Firm Remedio Raises $65 Million in First Funding Round Security Week News
Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza Microsoft Reduces Israel’s Access to Cloud and AI Products Over Reports of Mass Surveillance in Gaza Security Week News
AI Tools Used in Cyberattack on Mexican Water Utility AI Tools Used in Cyberattack on Mexican Water Utility Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat
  • ChatGPT Lockdown Mode Enhances Security Against Data Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark