Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mirai Botnet Exploits Vulnerability in Old D-Link Routers

Mirai Botnet Exploits Vulnerability in Old D-Link Routers

Posted on April 22, 2026 By CWS

Akamai has revealed that a Mirai botnet is actively exploiting a security flaw in discontinued D-Link routers. This vulnerability, identified as CVE-2025-29635, was first disclosed a year ago and remains a significant threat to users who have not retired these devices.

Understanding the Vulnerability

The vulnerability arises from a failure to validate an attacker-controlled function value, which can be manipulated through specially crafted POST requests. Akamai explains that the router processes data from the request body without verifying its source, allowing attackers to manipulate the command buffer.

This flaw is similar to a proof-of-concept exploit published on GitHub last year, which has since been removed. The attack involves loading a shell script to download and execute a payload with Mirai characteristics, such as XOR encoding and hardcoded execution strings.

Impact on D-Link Routers

The affected devices are part of the D-Link DIR-823X series, specifically firmware versions 240126 and 24082. These routers, having been discontinued last year, no longer receive software updates from D-Link, increasing the risk for users who continue to operate them.

In September, D-Link issued a warning advising users to retire these products to avoid potential security risks to connected devices. Despite this, exploitation attempts targeting these routers persist.

Wider Implications and Future Threats

Akamai notes that the attackers have also targeted vulnerabilities in TP-Link and ZTE routers, highlighting a broader threat across different brands. The ongoing Mirai malware campaigns leverage the original source code, which is easily accessible and often reused by both experienced and novice threat actors.

The low entry barrier and potential financial rewards continue to drive individuals towards engaging in botnet activities, posing ongoing challenges to cybersecurity efforts. Users are urged to upgrade to secure devices and remain vigilant against evolving threats.

As cyber threats continue to evolve, it is crucial for individuals and organizations to prioritize network security and take proactive measures to safeguard their systems.

Security Week News Tags:Akamai, botnet attacks, CVE-2025-29635, cyber threat, Cybersecurity, D-Link routers, discontinued products, IoT security, malware campaigns, Mirai botnet, network security, router firmware, TP-Link, Vulnerability, ZTE routers

Post navigation

Previous Post: Lotus Wiper Threatens Venezuela’s Energy Sector
Next Post: Global SIM Farm Network Reveals 87 Control Panels

Related Posts

CPAP Medical Data Breach Impacts 90,000 People CPAP Medical Data Breach Impacts 90,000 People Security Week News
Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities Russia’s APT28 Targeting Energy Research, Defense Collaboration Entities Security Week News
Anthropic AI Exposes Security Gaps in U.S. Systems Anthropic AI Exposes Security Gaps in U.S. Systems Security Week News
Google Awards  Million in 2025 Bug Bounty Payouts Google Awards $17 Million in 2025 Bug Bounty Payouts Security Week News
DHS Database Breach and Adobe’s Security Enhancements DHS Database Breach and Adobe’s Security Enhancements Security Week News
Bluekit Phishing Kit Leverages AI for Advanced Features Bluekit Phishing Kit Leverages AI for Advanced Features Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released
  • AWS Kiro Vulnerability Enables Remote Code Execution
  • ASUS Fixes Critical Router Flaw Allowing Remote Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Kali365 Exploits Microsoft Codes to Breach Accounts
  • Hackers Exploit MFA to Hijack Microsoft 365 Sessions
  • Windows NT Kernel Vulnerability PoC Publicly Released
  • AWS Kiro Vulnerability Enables Remote Code Execution
  • ASUS Fixes Critical Router Flaw Allowing Remote Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark