New Mirai botnet variant exploits nine vulnerabilities in SonicWall, D-Link, Netgear, and other devices, with attacks ongoing at publication.
Unit 42 observed attacks exploiting VisualDoor (SonicWall SSL-VPN), CVE-2020-25506 (D-Link DNS-320), CVE-2020-26919 (Netgear ProSAFE Plus), and other flaws, with infrastructure rotating across at least three IP addresses between February 16 and March 13, 2021. Payloads were updated hours after CVE-2021-27561 and CVE-2021-27562 (Yealink Device Management, unauthenticated root RCE) and later added CVE-2021-22502 (Micro Focus Operation Bridge Reporter) and CVE-2019-19356 (Netis WF2419). Successful exploitation invokes wget to fetch shell scripts that download Mirai binaries compiled for multiple architectures and brute-forcers, and attacks were still ongoing when reported.
Unit 42 observed the MooBot Mirai variant exploiting four D-Link vulnerabilities to compromise unpatched routers for use in DDoS attacks.
Unit 42 captured attacks exploiting four D-Link remote code execution vulnerabilities: CVE-2015-2051, CVE-2018-6530, CVE-2022-26258, and CVE-2022-28958, with three rated critical at CVSS 9.8. The exploits download the MooBot malware, a Mirai botnet variant, from infrastructure at 159.203.15.179 via wget. Compromised devices fall under full attacker control and can be used for distributed denial-of-service attacks. D-Link has published bulletins for all four flaws, but unpatched devices remain exposed.
Command Injection in D-Link DNS-320 system_mgr.cgi Allows Remote Code Execution
CVE-2020-25506 is an operating system command injection flaw (CWE-78) in the system_mgr.cgi component of D-Link DNS-320 network-attached storage devices. An attacker can trigger it by sending crafted input to the system_mgr.cgi handler of the device's web management interface, causing attacker-controlled data to be executed as operating system commands. Successful exploitation may allow remote code execution on the NAS, giving an attacker control over the device and its stored data. Any D-Link DNS-320 running affected firmware is at risk; the available data does not specify affected or fixed version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and current EPSS assigns roughly a 100% probability of exploitation within 30 days, though a specific ransomware association has not been confirmed.
· D-Link DNS-320 (network-attached storage device) KEV PoC large
Unauthenticated Root Command Injection in Yealink Device Management
CVE-2021-27561 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in Yealink Device Management (DM) 3.6.0.20, which CISA also characterizes as a server-side request forgery issue. A remote attacker can send a crafted, unauthenticated HTTP request to the /sm/api/v1/firewall/zone/services URI to inject operating system commands that execute with root privileges on the DM server. Successful exploitation yields full root control of the management server, allowing an attacker to pivot into the managed VoIP/UC environment, move laterally inside the network, or enroll the host in an IoT-style botnet. The flaw affects organizations running Yealink Device Management to administer fleets of Yealink IP phones, and it is trivially exploitable over the network with no user interaction. It was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and the recent emergence of Mirai-variant botnets targeting network devices is consistent with active mass-scanning for this class of unauthenticated injection flaw; EPSS puts the 30-day exploitation probability at roughly 83%.
· Yealink Device Management 3.6.0.20 confirmed affected (command injection as root); other/prior versions not specified in the source data KEVmoderate
Unauthenticated Remote Command Execution in D-Link DIR-820L Router
CVE-2022-26258 is an unauthenticated OS command injection (CWE-78) in D-Link DIR-820L router firmware, confirmed in version 1.05B03, reachable through the HTTP POST 'get set ccp' command interface. A remote attacker with no credentials and no user interaction can send a crafted HTTP POST request to this endpoint to execute arbitrary operating-system commands on the device. Successful exploitation yields full control of the router, providing a foothold for traffic interception, device enlistment into botnets, and lateral access to the home or small-office network behind it. Only users running the affected D-Link DIR-820L, an end-of-life consumer router, are affected, and no fixed firmware version is provided in the available data. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08 with a 92% EPSS score, and public reporting describes the Mirai-variant MooBot botnet targeting vulnerable D-Link devices.
· D-Link DIR-820L router firmware 1.05B03 confirmed affected; the product is end-of-life and no fixed version is specified in the available data KEV PoC ×2large
Unauthenticated OS Command Injection in D-Link DIR-860L/865L/868L/880L Routers
CVE-2018-6530 is an unauthenticated OS command injection flaw (CWE-78) in the SOAP interface (soap.cgi, handled by soapcgi_main in the cgibin binary) of several D-Link routers. A remote attacker sends a crafted request to soap.cgi containing a malicious 'service' parameter, causing arbitrary OS commands to execute on the router with no credentials or user interaction required. Successful exploitation yields full command execution on the device, enabling takeover, credential theft, or recruitment into botnets. Affected users are anyone running a D-Link DIR-860L, DIR-865L, DIR-868L, or DIR-880L on firmware at or below the versions listed in the advisory. Exploitation is active in the wild: CISA added the flaw to the KEV catalog on 2022-09-08 with known ransomware use, the Mirai variant MooBot/Moobot has been exploiting vulnerable D-Link routers to build botnets, and EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile).
· D-Link DIR-880L firmware DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and all previous versions · D-Link DIR-868L firmware DIR868LA1_FW112b04 and all previous versions KEV ransomware PoC mass
Missing Function-Level Access Control in NETGEAR JGS516PE Smart Managed Switches
CVE-2020-26919 is a missing function-level access control flaw in NETGEAR JGS516PE ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switches running firmware before 2.6.0.43. An unauthenticated remote attacker can invoke privileged switch functions over the network without authorization, consistent with the CVSS 9.8 critical score (network vector, no privileges or user interaction required). Successful exploitation grants the attacker full functional control of the switch's management functions, with high impact on confidentiality, integrity, and availability of the device. Any organization or site running a JGS516PE switch on affected firmware is exposed, particularly where the management interface is reachable from untrusted networks. The flaw is listed in the CISA Known Exploited Vulnerability Catalog (added 2021-11-03), indicating it is known to be exploited in the wild, and related reporting on Mirai variants targeting network devices suggests active scanning and botnet interest in this class of equipment.
· NETGEAR JGS516PE firmware (ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switch) All firmware versions before 2.6.0.43 KEVlarge
Unauthenticated Command Injection RCE in Micro Focus Operation Bridge Reporter
CVE-2021-22502 is an unauthenticated OS command injection flaw (CWE-78) in Micro Focus Operation Bridge Reporter (OBR) version 10.40, rated critical (CVSS 9.8) because it is reachable over the network with no privileges or user interaction required. By sending crafted input to the exposed OBR service, an attacker can inject operating-system commands that are executed directly on the OBR server. Successful exploitation yields full remote code execution with the privileges of the affected service, giving attackers a foothold in enterprise IT operations environments. Organizations running OBR 10.40 — an enterprise IT-operations analytics/reporting server — are affected, particularly where the OBR interface is reachable from untrusted networks. Exploitation status is high-concern: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, a public proof-of-concept for unauthenticated command injection exists, and EPSS puts the 30-day exploitation probability at 96.7% (top percentile).
Command Injection RCE as Root in Netis WF2419 Routers
Netis WF2419 routers contain an operating-system command injection flaw (CWE-78) in the router's web management page that allows an attacker to execute arbitrary commands with root privileges. The flaw is triggered through the web management interface, where crafted input is passed to a system command without adequate sanitization, enabling unauthenticated or low-privilege access to escalate to full command execution as root. An attacker who exploits it gains complete control of the router — root-level code execution — which can be used to intercept or manipulate traffic, pivot into the local network, or enlist the device in a botnet. Any user or organization running a Netis WF2419 router is affected, with the greatest risk on devices whose web management page is reachable from the WAN/internet. Although no public proof-of-concept is known and no CVSS score is published, CISA added the issue to the Known Exploited Vulnerabilities catalog on 2021-11-03 (confirming in-the-wild exploitation; ransomware use not reported), and the 98th-percentile EPSS of 28.2% indicates an elevated probability of exploitation over the next 30 days.
Out-of-Bounds Write in Arm Trusted Firmware-M Through 1.2
Arm Trusted Firmware-M (TF-M), the open-source reference secure firmware for Cortex-M microcontrollers with TrustZone, through version 1.2 contains an out-of-bounds write (CWE-787) in the non-secure processing environment (NSPE) handler-mode path. The flaw is triggered when software running in the non-secure world calls a secure function while in handler mode, which can corrupt memory or secure state. A successful trigger can halt the system, overwrite secure data, or print secure data to output; the scored impact is high availability (CVSS 3.1: 5.5, AV:L/PR:L), so exploitation requires local code execution in the non-secure world. Any device whose firmware is built on TF-M 1.2 or earlier is affected, spanning the many silicon vendors and IoT products that ship Arm's reference secure firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, though no public PoC is documented and ransomware use is unknown.
· trustedfirmware (Arm Trusted Firmware-M project) Trusted Firmware-M through 1.2 (all versions up to and including 1.2) KEVmass
Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router
The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life.
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.