ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-6271
Arbitrary Code Execution in GNU Bash (Shellshock)

GNU Bash through version 4.3 improperly processes trailing strings that follow function definitions inside environment variable values, allowing injected commands to run (CWE-78, OS command injection); this flaw is widely known as 'Shellshock'. An attacker triggers it by supplying a crafted environment variable to any service that invokes Bash, most notably CGI web handlers but also SSH, DHCP clients, and other software that sets variables and spawns the shell. Successful exploitation yields arbitrary code execution with the privileges of the Bash process on the target host. Any Linux, Unix, or similar system running an unpatched Bash through 4.3 is affected, including web servers, appliances, and embedded devices that ship the shell. Exploitation is confirmed in the wild: the flaw is in CISA's KEV (added 2022-01-28) with a required action to apply vendor updates, and EPSS assigns it a 100% probability of exploitation within 30 days, so patching is urgent.

Do: Apply Bash updates per your OS vendor's instructions, as required by the CISA KEV listing, ensuring the installed shell is a patched build newer than the unpatched 4.3-era code. Prioritize internet-exposed systems that pass environment variables to Bash, especially CGI-based web servers, and audit embedded appliances and other Linux/Unix hosts that may have been missed by standard patching.

100% KEV
  • GNU Bourne-Again Shell (Bash) all versions through 4.3 (unpatched builds)
masshundreds of millions of installations, with hundreds of thousands to 1M+ internet-exposed systems
CVE-2015-2051
Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router

The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life.

Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation.

97% KEV
  • D-Link DIR-645 Wired/Wireless Router
largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution)
CVE-2016-6277
Unauthenticated RCE via Command Injection in NETGEAR Multiple Routers

Multiple NETGEAR router models allow unauthenticated web pages to pass form input directly to the device's command-line interface, which permits remote code execution (CVE-2016-6277). An attacker triggers the flaw by sending a crafted HTTP request to the router's web interface without logging in, causing attacker-supplied input to be interpreted as commands on the router. Successful exploitation grants the ability to run arbitrary commands on the device, typically with root privileges, enabling full takeover of the router and use as a pivot point into the network behind it. Any NETGEAR router among the affected models running firmware without the vendor patch is vulnerable, with internet-facing management interfaces at greatest risk. The flaw was added to CISA's Known Exploited Vulnerability catalog on 2022-03-07, indicating exploitation in the wild, and it carries a very high 99.8% EPSS probability of exploitation within 30 days.

Do: Update affected NETGEAR routers to the latest available firmware for the specific model, per the vendor's upgrade instructions, as required by CISA's KEV listing. As interim mitigation, disable WAN-side/remote management and restrict the router's admin interface to the local network, then review devices for signs of compromise such as unexpected configuration changes or added accounts.

8.8100% KEV PoC ×3
  • NETGEAR
masslikely 100,000+ internet-exposed NETGEAR routers (exact count unknown)
CVE-2017-18368
Unauthenticated OS Command Injection in Zyxel/Billion TrueOnline Routers

CVE-2017-18368 is a critical (CVSS 9.8) unauthenticated OS command injection (CWE-78) in the Remote System Log forwarding function of Zyxel P660HN-T1A (v1 and v2) and Billion 5200W-T routers distributed by Thailand ISP TrueOnline. An unauthenticated attacker who can reach the router's web management interface sends a crafted remote_host parameter to the ViewLog.asp page, with no credentials or user interaction required. Successful injection executes arbitrary operating-system commands on the device, giving the attacker full control of the router (e.g., botnet recruitment, traffic/DNS manipulation, or pivoting into the subscriber's LAN). Only TrueOnline-issued units of these models are affected, meaning Thai broadband subscribers deployed with this CPE. The flaw is in CISA's KEV catalog (added 2023-08-07), carries a 94.4% EPSS (100th percentile), and related reporting shows IoT botnets (e.g., Gafgyt campaigns against End-of-Life Zyxel routers and multi-exploit campaigns like RondoDox) actively targeting such devices.

Do: Update affected routers to the latest firmware available from Zyxel/Billion or via TrueOnline's ISP update process, noting these models are End-of-Life so hardware replacement is the durable fix. Until patched, restrict or disable WAN-side access to the router's web management interface (the flaw is reachable unauthenticated via ViewLog.asp) and audit devices for signs of botnet compromise. Per the CISA KEV required action, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

9.894% KEV PoC ×3
  • Zyxel P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 (TrueOnline-distributed firmware; model listed broadly as affected by CISA)
  • Zyxel P660HN-T1A v2
  • Billion 5200W-T
mass≈1 million (order-of-magnitude estimate) TrueOnline-issued devices, of which thousands to tens of thousands expose the management interface to the internet at…
CVE-2017-18369
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is

The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through the syslogServerAddr parameter.

NVD description · AI analysis pending
9.868% PoC ×3
  • billion 5200w-t firmware
CVE-2018-10561
Authentication Bypass in Dasan GPON Home Routers (CVE-2018-10561)

CVE-2018-10561 is a critical authentication bypass (CWE-287, CVSS 9.8) in Dasan GPON home router firmware: the devices fail to properly enforce login when a specific suffix is added to a URL. An attacker simply appends "?images" to any protected URL — for example /menu.html?images/ or /GponForm/diag_FORM?images/ — and the router treats the request as already authenticated. Once bypassed, the attacker gains full access to the device's management interface, enabling configuration changes, diagnostics, and use of the router as a botnet node or network pivot. All Dasan Gigabit Passive Optical Network (GPON) routers running the affected firmware are exposed, especially units with their web interface reachable from the internet; CISA notes the impacted product is end-of-life. Exploitation is active and widespread: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-31), carries a 92.9% EPSS probability of exploitation within 30 days, and IoT botnets have historically targeted these routers.

Do: CISA's required action is to disconnect or replace these routers if still in use, since the product is end-of-life and should not remain deployed. As an interim mitigation, remove the device's web management interface from internet exposure and block or strip requests containing "?images"; verify exposure by loading /menu.html?images/ without logging in — if it returns the management page, the device is vulnerable. A community mitigation tool and unofficial patch have been published by researchers, but replacement remains the recommended fix, and defenders should expect continued botnet scanning of exposed units.

9.893% KEV PoC ×2
  • Dasan Networks GPON home router firmware (Dasan Gigabit Passive Optical Network Routers)
massseveral hundred thousand internet-exposed routers (10^5-10^6 range)
CVE-2018-11714
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 R

An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.

NVD description · AI analysis pending
9.868% PoC ×2
  • tp-link tl-wr840n firmware
  • tp-link tl-wr841n firmware
CVE-2019-1663
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco R

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user. RV110W Wireless-N VPN Firewall versions prior to 1.2.2.1 are affected. RV130W Wireless-N Multifunction VPN Router versions prior to 1.0.3.45 are affected. RV215W Wireless-N VPN Router versions prior to 1.3.1.1 are affected.

NVD description · AI analysis pending
9.896% PoC ×2
  • cisco rv110w firmware
  • cisco rv130w firmware
  • cisco rv215w firmware
CVE-2019-16920
Command Injection in Multiple D-Link Routers Enables Full Device Compromise

Multiple D-Link routers contain a command injection flaw (CWE-78) in which attacker-controlled input is executed as operating system commands by the device. An attacker who triggers the flaw can run arbitrary commands on the router with system privileges, achieving full compromise of the device, from which they can intercept or redirect traffic, pivot to the local network, or persist on the device. The specific affected models and firmware version ranges are not enumerated in the available data, but CISA notes the impacted product line is end-of-life, so only devices still in service are at risk. This vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25, and EPSS assigns it a 100% probability of exploitation within 30 days (100th percentile). No public proof-of-concept is known, but the KEV listing means defenders should treat exploitation as active, not theoretical.

Do: Inventory your environment for D-Link routers and identify any running the affected end-of-life models; per CISA's required action, disconnect or retire them if still in use since they no longer receive fixes. If a device must remain in service, restrict management access (disable WAN-side web administration, limit it to trusted management networks) and monitor for compromise indicators. Confirm whether any internet-facing D-Link routers are exposed and prioritize replacement of EOL units.

9.8100% KEV PoC ×2
  • D-Link
massplausibly hundreds of thousands of internet-exposed D-Link routers and millions sold overall; exact count of in-use affected units unknown
CVE-2020-10987
Unauthenticated OS Command Injection in Tenda AC15 AC1900 Router

CVE-2020-10987 is an unauthenticated OS command injection flaw (CWE-78) in the goform/setUsbUnload endpoint of the Tenda AC15 AC1900 router, demonstrated on firmware version 15.03.05.19. An attacker triggers it by sending a crafted deviceName POST parameter to that endpoint, which is not properly sanitized before being used in a system command. Successful exploitation yields arbitrary remote code execution on the router, giving the attacker full control of the device and a foothold to pivot into the local network, as is typical for IoT botnet recruitment. Owners of Tenda AC15 routers are affected, with greatest risk on units whose web administration interface is reachable from the internet. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 79.8% EPSS score (top percentile), and a public proof of concept has been available since its 2020 disclosure; ransomware use is unknown.

Do: Apply the latest Tenda AC15 firmware available from the vendor (newer than 15.03.05.19) per CISA's required action and vendor instructions. Until patched, disable or restrict WAN-side remote web administration to trusted source IPs, since the flaw is exploitable without credentials over the network. Check router HTTP logs for unexpected POST requests to /goform/setUsbUnload containing suspicious deviceName values, and monitor for botnet-style command activity.

9.880% KEV PoC
  • Tenda AC15 AC1900 router firmware Firmware version 15.03.05.19 (the only version named in the advisory; the full affected version range is not specified, so other AC15 firmware releases may also
moderateLikely on the order of thousands to tens of thousands of remotely exploitable Tenda AC15 units (estimate; no authoritative install-base or scan count provided).
CVE-2020-25506
Command Injection in D-Link DNS-320 system_mgr.cgi Allows Remote Code Execution

CVE-2020-25506 is an operating system command injection flaw (CWE-78) in the system_mgr.cgi component of D-Link DNS-320 network-attached storage devices. An attacker can trigger it by sending crafted input to the system_mgr.cgi handler of the device's web management interface, causing attacker-controlled data to be executed as operating system commands. Successful exploitation may allow remote code execution on the NAS, giving an attacker control over the device and its stored data. Any D-Link DNS-320 running affected firmware is at risk; the available data does not specify affected or fixed version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and current EPSS assigns roughly a 100% probability of exploitation within 30 days, though a specific ransomware association has not been confirmed.

Do: Apply D-Link firmware updates for the DNS-320 per the vendor's instructions, as required by CISA's KEV listing. Until patched, stop exposing the device's web interface to the internet (remove port forwarding/DMZ rules or restrict access to trusted management networks). Because exploitation is being observed, check NAS logs for unexpected requests to system_mgr.cgi and signs of unauthorized command execution.

9.8100% KEV PoC
  • D-Link DNS-320 (network-attached storage device)
largetens of thousands of internet-exposed DNS-320 devices (estimate; total installed base likely higher)
CVE-2020-27867
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2,

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. When parsing the funjsq_access_token parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-11653.

NVD description · AI analysis pending
6.82%
  • netgear ac2100 firmware
  • netgear ac2400 firmware
  • netgear ac2600 firmware
  • +1 more
CVE-2021-41773
Path Traversal to RCE in Apache HTTP Server 2.4.49

Apache HTTP Server contains a path traversal flaw (CWE-22) that lets crafted HTTP requests reach files outside directories configured via Alias-like directives. When files outside those aliased directories are not protected by the default 'require all denied' policy, attackers can read arbitrary files outside the intended root, and if CGI scripts are enabled the traversal can be escalated to remote code execution under the web server account. Anyone running an affected Apache HTTP Server release with such a configuration is exposed; the initial 2.4.50 patch was incomplete, so the flaw's full remediation is tracked under CVE-2021-42013. Exploitation is confirmed in the wild: CISA added the vulnerability to the KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns a ~100% probability of exploitation within 30 days (100th percentile).

Do: Upgrade to Apache HTTP Server 2.4.51 or later; do not stop at 2.4.50, since its fix was incomplete (see CVE-2021-42013). As an interim mitigation, ensure directories referenced by Alias-like directives are covered by 'require all denied' and disable or restrict CGI (mod_cgi/mod_cgid) on traversable paths. Review access logs for traversal patterns such as /icons/../ and unexpected CGI invocations, and hunt for webshells or ransomware staging given the known ransomware use.

9.8100% KEV ransomware PoC ×6
  • Apache HTTP Server 2.4.49 per public advisories (the 2.4.50 fix was incomplete; fully fixed in 2.4.51 via CVE-2021-42013)
masson the order of 100,000+ internet-exposed Apache servers
CVE-2021-42013
Path Traversal and RCE in Apache HTTP Server (follow-up to CVE-2021-41773)

Apache HTTP Server contains a path traversal flaw (CWE-22) that can lead to remote code execution; CVE-2021-42013 resolves an incomplete patch previously issued for CVE-2021-41773. The flaw is triggered when files outside directories mapped by Alias-like directives are not protected by the default 'require all denied' configuration, or when CGI scripts are enabled, allowing an attacker to traverse outside the intended directory roots. An attacker can read files outside the configured paths, and where CGI script execution is enabled, achieve remote code execution on the server. The affected product per CISA is Apache HTTP Server; the source data does not specify exact version ranges, so defenders should consult the vendor advisory for fixed releases. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS estimates a 100% probability of exploitation within 30 days, and no public PoC is listed.

Do: Apply the Apache HTTP Server update per vendor instructions immediately, since this is a CISA KEV item with known ransomware use and near-certain near-term exploitation. Until patched, ensure directories targeted by Alias-like directives are covered by 'require all denied' defaults and disable CGI script execution where it is not required. Review access logs for path traversal probes and confirm no replaced version retains the incomplete earlier patch.

9.8100% KEV ransomware PoC ×6
  • Apache HTTP Server
massorder of 100,000+ internet-exposed Apache HTTP Server instances at disclosure time
CVE-2022-36553
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

NVD description · AI analysis pending
9.891%
  • hytec hwl-2511-ss firmware
CVE-2022-37129
D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand.

D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in the command parameter, it will be spliced into byte_4836B0 by snprintf, and finally doSystem(&byte_4836B0); will be executed, resulting in a command injection.

NVD description · AI analysis pending
8.88% PoC
  • dlink dir-816 firmware
CVE-2022-44149
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field

The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required

NVD description · AI analysis pending
8.864% PoC ×4
  • nexxtsolutions amp300 firmware
CVE-2023-1389
Command Injection in TP-Link Archer AX21 Router Allows Remote Code Execution

CVE-2023-1389 is a command injection flaw (CWE-77) in TP-Link's Archer AX21 Wi-Fi 6 router that lets an attacker execute arbitrary operating-system commands on the device. It is triggered by sending crafted input to a remotely reachable service on the router, which passes attacker-controlled values to the device's shell without proper sanitization; the source data does not specify the vulnerable endpoint or exact affected firmware ranges. Successful exploitation yields remote code execution on the router, giving the attacker a foothold in the network where the router sits, from which they can pivot or abuse the device further. Any household or organization running an Archer AX21 router is affected, with the highest risk where the router's management interface is exposed to the internet. The flaw was added to CISA's KEV catalog on 2023-05-01, confirming exploitation in the wild; EPSS assigns a ~100% probability of exploitation within 30 days (top percentile), while no public proof-of-concept or ransomware association is documented in the source data.

Do: Update the Archer AX21 to the latest firmware available from TP-Link per the vendor's instructions (fixed firmware is published on the product's TP-Link support page). If updating is not immediately possible, disable WAN-side/remote management and restrict the router's web interface to the local network. Because exploitation is confirmed in the wild, also review exposed routers for signs of compromise, such as unexplained configuration changes or unexpected outbound traffic.

8.8100% KEV PoC ×2
  • TP-Link Archer AX21 (Archer AX-21) Wi-Fi 6 router
masslikely hundreds of thousands of routers deployed, with >100k plausibly internet-exposed
CVE-2023-25280
Unauthenticated OS Command Injection in D-Link DIR-820 Router (CVE-2023-25280)

CVE-2023-25280 is an unauthenticated OS command injection flaw (CWE-78) in D-Link DIR-820 router firmware DIR820LA1_FW105B03, located in the ping.ccp web interface. A remote attacker with no credentials can send a crafted ping_addr parameter to ping.ccp, causing arbitrary operating-system commands to execute on the router. Successful exploitation escalates privileges to root, giving an attacker full control of the device for use as a botnet node or a foothold into the connected network. Users running the affected D-Link DIR-820 hardware are exposed, and because the product is end-of-life/end-of-service, fixes are not expected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-30, EPSS puts the 30-day exploitation probability at 97.9% (100th percentile), a public proof-of-concept is available, and active botnet campaigns such as RondoDox and Mirai-style campaigns are targeting flaws in this class of IoT devices.

Do: Per CISA's KEV required action, discontinue use of this end-of-life/end-of-service product — retire or replace the DIR-820, since no patched firmware is expected. If replacement must be delayed, restrict the router's web interface so it is not reachable from the WAN, disable remote management, and monitor for signs of botnet infection such as unusual outbound traffic. When inventorying, verify installed firmware version (affected build: DIR820LA1_FW105B03).

9.898% KEV PoC
  • D-Link DIR-820 (DIR-820L) router DIR8LA1_FW105B03 firmware (the version named in the advisory; no other version ranges were specified)
moderatelikely tens of thousands of internet-exposed units (estimated; no authoritative public scan count for this single end-of-life model)
CVE-2023-26801
LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulne

LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.

NVD description · AI analysis pending
9.870% PoC
  • lb-link bl-lte300 firmware
  • lb-link bl-x26 firmware
  • lb-link bl-wr9000 firmware
  • +1 more
CVE-2023-47565
Authenticated OS Command Injection in QNAP VioStor NVR (QVR Firmware 4.x)

CVE-2023-47565 is an OS command injection vulnerability (CWE-78) affecting legacy QNAP VioStor NVR models running QVR Firmware 4.x, rated 8.8 (High) on the CVSS 3.1 scale. An authenticated user can send crafted input over the network that the device passes to the underlying operating system, triggering arbitrary command execution. Successful exploitation allows the attacker to run OS commands on the NVR, which typically means full compromise of the device for data access, lateral movement, or enrollment into botnets such as the Mirai-based InfectedSlurs campaign. Only organizations still operating legacy VioStor NVR hardware on QVR 4.x are affected; QNAP fixed the vulnerability in QVR Firmware 5.0.0 and later. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, EPSS assigns a 73.3% probability of exploitation within 30 days (99th percentile), and the InfectedSlurs botnet has been reported actively targeting it.

Do: Upgrade affected legacy VioStor NVRs to QVR Firmware 5.0.0 or later; per CISA's KEV required action, apply vendor mitigations or discontinue use of any unit that cannot be updated. Remove internet exposure of the NVR web interface where possible, verify the running QVR firmware version on each device, and hunt for signs of botnet infection (unusual outbound traffic or processes) given confirmed in-the-wild exploitation.

8.873% KEV
  • QNAP VioStor NVR (QVR Firmware) QVR Firmware 4.x on legacy VioStor NVR models; fixed in QVR Firmware 5.0.0 and later
large≈tens of thousands of internet-exposed legacy VioStor NVR devices (estimate)
CVE-2023-51833
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi p

A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.

NVD description · AI analysis pending
8.14% PoC
  • trendnet tew-411brpplus firmware
CVE-2023-52163
Missing Authorization Enables Command Injection in Digiever DS-2105 Pro NVRs

Digiever DS-2105 Pro network video recorders (firmware version 3.1.0.71-11 is cited in the advisory) expose a time_tzsetup.cgi endpoint that fails to properly enforce authorization (CWE-862), and crafted requests to it trigger operating-system command injection; the CVSS 8.8 score reflects network reachability, low privilege requirements, and no user interaction. Successful exploitation yields command execution on the device with high impact on confidentiality, integrity, and availability — effectively remote code execution, which makes these NVRs attractive targets for IoT botnets such as the RondoDox campaign and the Mirai-variant ShadowV2. Only organizations still running the DS-2105 Pro (or DS-2105 Pro+) are affected, and because the vendor no longer supports the product, unpatched internet-facing units are the primary risk. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-12-22, EPSS puts the 30-day exploitation probability at 96.9%, and ransomware use is currently unknown.

Do: Because the product is end-of-life, check with Digiever for any final firmware update and apply it per vendor instructions; if no patch or mitigation is available, the CISA KEV required action is to discontinue use of the device, and federal agencies must follow BOD 22-01 timelines. In the interim, remove direct internet exposure of the NVR's web interface (restrict via firewall or place behind VPN) and hunt for compromise by looking for suspicious requests to time_tzsetup.cgi and unexpected outbound connections consistent with botnet infection.

8.897% KEV PoC ×3
  • Digiever DS-2105 Pro NVR firmware 3.1.0.71-11 (the version named in the advisory; the product is end-of-life and no longer supported)
  • Digiever DS-2105 Pro+ NVR firmware
moderatelikely on the order of thousands of internet-exposed NVRs (estimated; exact install base unknown)
CVE-2024-10914
OS Command Injection in D-Link DNS-320/320LW/325/340L NAS Firmware

CVE-2024-10914 is a critical OS command injection flaw (CWE-74/CWE-78/CWE-707) in the cgi_user_add function of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add on D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L network-attached storage devices. A remote, unauthenticated attacker can trigger it by manipulating the 'name' argument sent to that CGI endpoint, injecting operating system commands that the device executes. Successful exploitation yields arbitrary command execution on the NAS, giving the attacker control of the device — a profile attractive for follow-on actions such as botnet recruitment, consistent with recent IoT botnet activity. Affected devices are the DNS-320, DNS-320LW, DNS-325, and DNS-340L, which news reports describe as end-of-life D-Link NAS models, with all firmware up to 20241028 listed as vulnerable. A public proof-of-concept is available, the EPSS score is 96.2% (top percentile, indicating very high likelihood of exploitation within 30 days), and news headlines indicate hackers are actively targeting the flaw, though it is not yet in CISA KEV.

Do: Owners of DNS-320, DNS-320LW, DNS-325, and DNS-340L devices should check D-Link's support pages for updated firmware or end-of-life guidance and apply any fix the vendor publishes. Because the flaw is reachable via /cgi-bin/account_mgr.cgi?cmd=cgi_user_add, block or restrict remote (WAN) access to the device's web management interface — and consider blocking that specific endpoint — until patched; these EOL devices may never receive an update, in which case retiring or isolating them behind a restricted network is the safest option.

9.296% PoC
  • D-Link DNS-320 firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-320LW firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-325 firmware up to and including 20241028 (all listed firmware)
  • +1 more
large≈ tens of thousands of internet-exposed NAS devices (10k–100k range; exact counts unknown)
CVE-2024-12847
Unauthenticated Root RCE in NETGEAR DGN1000 via setup.cgi

CVE-2024-12847 is an authentication bypass (CWE-306) in NETGEAR DGN1000 routers that allows a remote, unauthenticated attacker to inject and execute arbitrary operating system commands (CWE-78) as root. The flaw is triggered by sending crafted HTTP requests to the device's setup.cgi endpoint; no credentials or user interaction are required, and the network vector and low complexity yield a critical CVSS 3.1 score of 9.8. A successful attacker gains full root control of the router, which can be used for device compromise, traffic interception, or botnet recruitment. All DGN1000 units running firmware before 1.1.00.48 are affected; these are aging consumer/ISP-supplied routers, many of which remain connected to the public internet with management interfaces exposed. The vulnerability has been exploited in the wild since at least 2017 and was specifically observed by the Shadowserver Foundation on 2025-02-06 UTC; it has two public PoCs on Exploit-DB, a 29.9% EPSS (98th percentile), is not yet in CISA KEV, and broader botnet activity against consumer routers (e.g., RondoDox, reported to target 56 flaws across 30+ device types) suggests continued scanning pressure against this device class.

Do: Upgrade affected DGN1000 units to firmware 1.1.00.48 or later; if the device is end-of-life or no update is available, block or restrict WAN-side access to the web management interface (particularly setup.cgi) or replace the router. Review device and firewall logs for suspicious unauthenticated requests to setup.cgi, and treat any unit with an internet-exposed management interface as potentially compromised given exploitation has been observed since at least 2017.

9.830% PoC ×2
  • netgear dgn1000 firmware before 1.1.00.48
largeon the order of 10,000-100,000 internet-exposed DGN1000 devices (total units shipped over the product's lifetime likely higher)
CVE-2024-12856
OS Command Injection in Four-Faith F3x24/F3x36 Routers

Four-Faith industrial router models F3x24 and F3x36 running firmware version 2.0 are vulnerable to OS command injection (CWE-78) through the apply.cgi interface when an attacker modifies the system time over HTTP. The flaw is technically authenticated (CVSS 3.1: 7.2, network-adjacent-remote with high privileges required), but the same firmware ships with default credentials, so any device where defaults were not changed is effectively exposed to unauthenticated remote OS command execution. A successful attacker can run arbitrary commands on the router, gaining full device compromise that can be used for further access or recruitment into botnets. Four-Faith deployments — typically industrial and remote-connectivity routers — are affected, with at least 15,000 routers exposed to the internet and many retaining default credentials. Exploitation is confirmed in the wild: a Mirai botnet variant has weaponized the flaw for DDoS attacks, and the RondoDox botnet is also targeting it, consistent with a high EPSS score (84.2% probability of exploitation within 30 days, 100th percentile).

Do: Update F3x24/F3x36 devices to the latest firmware available from Four-Faith and verify apply.cgi handling is fixed; as an immediate mitigation, change default administrator credentials and restrict HTTP management access to trusted networks. Check devices for signs of botnet infection (unexpected outbound traffic or Crontab/persistence changes) and prioritize patching given confirmed in-the-wild exploitation by Mirai and RondoDox botnets.

7.284% PoC ×2
  • Four-Faith F3x24 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
  • Four-Faith F3x36 router firmware at least firmware version 2.0 (exact affected version range not specified in the data)
large≈15,000+ internet-exposed routers (headline scan count; total deployments likely higher)
CVE-2024-1781
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719.

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
9.815% PoC
  • totolink x6000r firmware
CVE-2024-3721
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical.

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.

NVD description · AI analysis pending
6.386%
CVE-2024-7029
Commands can be injected over the network and executed without authentication.

Commands can be injected over the network and executed without authentication.

NVD description · AI analysis pending
8.739% PoC
  • avtech avm1203 firmware
CVE-2025-1829
A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329.

A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329. It has been declared as critical. This vulnerability affects the function setMtknatCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument mtkhnatEnable leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.312% PoC
  • totolink x18 firmware
CVE-2025-22905
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

NVD description · AI analysis pending
9.85% PoC
  • edimax re11s firmware
CVE-2025-34037
Unauthenticated OS Command Injection in Linksys E-Series Routers

CVE-2025-34037 is an unauthenticated OS command injection flaw (CWE-78) in the /tmUnblock.cgi and /hndUnblock.cgi CGI scripts of various Linksys E-Series routers, reachable over HTTP on port 8080. An attacker sends HTTP requests with a crafted ttcp_ip parameter, which the scripts pass to the shell without sanitization, allowing injected shell commands to run on the device. Successful exploitation yields arbitrary command and code execution on the router — the 2014 "TheMoon" worm used this flaw to drop a MIPS ELF payload — enabling device takeover, persistence, or botnet enrollment. Various E-Series models are affected, and the flaw may also extend to other Linksys WAG/WAP/WES/WET/WRT-series routers and Wireless-N access points/routers. Exploitation was observed in the wild as recently as 2025-02-06 by the Shadowserver Foundation (and famously by TheMoon in 2014); the flaw carries a maximum-severity CVSS 4.0 score of 10 and a top-percentile 90.9% EPSS, related news of the RondoDox botnet targeting 56 flaws across 30+ device types underscores ongoing botnet pressure on router-class devices, and it is not yet listed in CISA KEV.

Do: Identify whether any Linksys router on your networks exposes its port 8080 HTTP management interface from untrusted/WAN networks and check whether /tmUnblock.cgi or /hndUnblock.cgi responds; if so, block or restrict port 8080 (or disable remote administration) until vendor firmware updates become available — no fixed version is specified in the available data. Hunt for signs of compromise consistent with TheMoon-style MIPS ELF payloads, such as unexpected processes or services, added backdoor listeners, and anomalous outbound traffic, and prioritize patching given the top-percentile EPSS (90.9%) and fresh in-the-wild exploitation.

10.091%
  • Linksys E-Series routers (various models; vulnerable /tmUnblock.cgi and /hndUnblock.cgi CGI endpoints over HTTP on port 8080)
  • Linksys Other router series and Wireless-N access points/routers (WAG/WAP/WES/WET/WRT-series; potentially affected, not limited
massOver 1M devices plausibly affected (Linksys E-Series sold in the millions during the early 2010s); the currently internet-exposed population is likely in the…
CVE-2025-4008
Unauthenticated Command Injection RCE in Smartbedded Meteobridge

The Meteobridge web interface, implemented in CGI shell scripts and C, exposes an endpoint vulnerable to command injection (CWE-77) with missing authentication requirements (CWE-306). A remote, unauthenticated attacker who can reach the web interface can supply crafted input that is passed to the underlying shell, gaining arbitrary command execution with root privileges on the device. Affected products are Smartbedded Meteobridge firmware and the Meteobridge VM, used to bridge weather-station data. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-10-02, and public reporting indicates it is being actively exploited in the wild; EPSS puts the 30-day exploitation probability at 93.7%. Exploitation details are documented in a public advisory by the discovering researcher (oneKey).

Do: Apply the fix or mitigations per the Smartbedded vendor instructions referenced in the CISA KEV entry (fixed version numbers are not specified in the source data, so consult the vendor advisory and the oneKey write-up before upgrading). Until patched, do not expose the Meteobridge web interface directly to the internet — restrict it to trusted management networks or via VPN/firewall rules — and check exposed instances for signs of compromise given confirmed in-the-wild exploitation. Organizations under BOD 22-01 must apply the required mitigations within the mandated timeframe or discontinue use of the product.

8.794% KEV PoC
  • Smartbedded Meteobridge firmware
  • Smartbedded Meteobridge VM
moderate≈1,000–10,000 internet-exposed Meteobridge instances (public scans historically show low thousands of exposed Meteobridge web interfaces; total installed base,…
CVE-2025-5504
A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical.

A vulnerability has been found in TOTOLINK X2000R 1.0.0-B20230726.1108 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formWsc. The manipulation of the argument peerRptPin leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.313% PoC
  • totolink x2000r firmware
CVE-2025-7414
A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880).

A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). This vulnerability affects the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument domain leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.113% PoC ×2
  • tenda o3 firmware
Full article671 words · extracted from securityaffairs.com · click to collapse

RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, CCTV systems, and servers, active globally since June.

Trend Micro researchers reported that the RondoDox botnet exploits 56 known flaws in over 30 device types, including DVRs, NVRs, CCTV systems, and web servers, active globally since June.

Experts noted that the latest RondoDox campaign adopts an “exploit shotgun” approach, firing multiple exploits to see which succeed.

In July, FortiGuard Labs first spotted the RondoDox botnet that was exploiting CVE-2024-3721 and CVE-2024-12856. Active since 2024, it uses custom libraries and mimics gaming or VPN traffic to evade detection.

Trend Micro first seen RondoDox activity on June 15, 2025, exploiting CVE-2023-1389 in TP-Link Archer AX21 routersm, a flaw first shown at Pwn2Own 2023 and still popular with botnets.

RondoDox now exploits multiple CVEs, including CVE-2024-3721 and CVE-2024-12856, evolving into a multivector loader targeting diverse devices.

Below are some of the vulnerabilities exploited in the RondoDox campaigns:

VendorProductCVE IDCWEType
D-LinkDNS-343 ShareCenter / goAhead Web ServerN/ACWE-78No CVE
TVTNVMS-9000 Digital Video Recorder (DVR)N/ACWE-78No CVE
LILINDVR (Variant A)N/ACWE-78No CVE
LILINDVR (Variant B)N/ACWE-78No CVE
FiberhomeRouter SR1041F RP0105N/ACWE-78No CVE
LinksysRouter apply.cgi (Variant A)N/ACWE-78No CVE
LinksysRouter apply.cgi (Variant B)N/ACWE-78No CVE
BYTEVALUEIntelligent Flow RouterN/ACWE-78No CVE
D-LinkDIR-645 & DIR-815N/ACWE-78No CVE
Unknownwlan_operate endpointN/ACWE-78No CVE
Unknownresize_ext2 endpointN/ACWE-78No CVE
ASMAX804 RouterN/ACWE-78No CVE
D-LinkDIR-X4860N/ACWE-78No CVE
UnknownFile Upload (upgrade form)N/ACWE-78No CVE
BrickcomIP CameraN/ACWE-78No CVE
IQrouterIQrouter 3.3.1N/ACWE-78No CVE
RiconIndustrial Cellular Router S9922XLN/ACWE-78No CVE
UnknownShell endpointN/ACWE-78No CVE
NexxtRouter FirmwareCVE-2022-44149CWE-78N-Day
D-LinkDIR-645 Wired/Wireless RouterCVE-2015-2051CWE-78N-Day
NetgearR7000 / R6400 RouterCVE-2016-6277CWE-78N-Day
NetgearMultiple Routers (mini_httpd)CVE-2020-27867CWE-78N-Day
ApacheHTTP ServerCVE-2021-41773CWE-22N-Day
ApacheHTTP ServerCVE-2021-42013CWE-22N-Day
TBKMultiple DVRsCVE-2024-3721CWE-78N-Day
TOTOLINKRouter (setMtknatCfg)CVE-2025-1829CWE-78N-Day
MeteobridgeWeb InterfaceCVE-2025-4008CWE-78N-Day
D-LinkDNS-320CVE-2020-25506CWE-78N-Day
DigieverDS-2105 ProCVE-2023-52163CWE-78N-Day
NetgearDGN1000CVE-2024-12847CWE-78N-Day
D-LinkMultiple ProductsCVE-2024-10914CWE-78N-Day
EdimaxRE11S RouterCVE-2025-22905CWE-78N-Day
QNAPVioStor NVRCVE-2023-47565CWE-78N-Day
D-LinkDIR-816CVE-2022-37129CWE-78N-Day
GNUBash (ShellShock)CVE-2014-6271CWE-78N-Day
DasanGPON Home RouterCVE-2018-10561CWE-287N-Day
Four-FaithIndustrial RoutersCVE-2024-12856CWE-78N-Day
TP-LinkArcher AX21CVE-2023-1389CWE-78N-Day
D-LinkMultiple ProductsCVE-2019-16920CWE-78N-Day
TendaRouter (fromNetToolGet)CVE-2025-7414CWE-78N-Day
TendaRouter (deviceName)CVE-2020-10987CWE-78N-Day
LB-LINKMultiple RoutersCVE-2023-26801CWE-78N-Day
LinksysE-Series Multiple RoutersCVE-2025-34037CWE-78N-Day
AVTECHCCTVCVE-2024-7029CWE-78N-Day
TOTOLINKX2000RCVE-2025-5504CWE-78N-Day
ZyXELP660HN-T1ACVE-2017-18368CWE-78N-Day
Hytec InterHWL-2511-SSCVE-2022-36553CWE-78N-Day
BelkinPlay N750CVE-2014-1635CWE-120N-Day
TRENDnetTEW-411BRPplusCVE-2023-51833CWE-78N-Day
TP-LinkTL-WR840NCVE-2018-11714CWE-78N-Day
D-LinkDIR820LA1_FW105B03CVE-2023-25280CWE-78N-Day
Billion5200W-T RouterCVE-2017-18369CWE-78N-Day
CiscoMultiple ProductsCVE-2019-1663CWE-119N-Day
TOTOLINKRouter (setWizardCfg)CVE-2024-1781CWE-78N-Day

“The latest RondoDox botnet campaign represents a significant evolution in automated network exploitation, demonstrating how threat actors continue to weaponize both publicly disclosed vulnerabilities and zero-day exploits discovered at security competitions like Pwn2Own.” states Trend Micro. “The campaign’s shotgun approach of targeting more than 50 vulnerabilities across over 30 vendors underscores the persistent risks facing organizations that maintain internet-exposed network infrastructure without adequate security controls.”

Even when vulnerabilities are reported and patched, attackers exploit them faster than before. Organizations that delay updates or don’t track their devices give threats like RondoDox a chance to stay in their systems.

“Moving forward, defenders must adopt a proactive security posture that includes regular vulnerability assessments, network segmentation to limit lateral movement, restrict internet exposure, and continuous monitoring for signs of compromise.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, botnet)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/183183/malware/rondodox-botnet-targets-56-flaws-across-30-device-types-worldwide.html