New Mirai variant ShadowV2 tests IoT exploits amid AWS disruption
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-25506 | Command Injection in D-Link DNS-320 system_mgr.cgi Allows Remote Code Execution CVE-2020-25506 is an operating system command injection flaw (CWE-78) in the system_mgr.cgi component of D-Link DNS-320 network-attached storage devices. An attacker can trigger it by sending crafted input to the system_mgr.cgi handler of the device's web management interface, causing attacker-controlled data to be executed as operating system commands. Successful exploitation may allow remote code execution on the NAS, giving an attacker control over the device and its stored data. Any D-Link DNS-320 running affected firmware is at risk; the available data does not specify affected or fixed version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and current EPSS assigns roughly a 100% probability of exploitation within 30 days, though a specific ransomware association has not been confirmed. Do: Apply D-Link firmware updates for the DNS-320 per the vendor's instructions, as required by CISA's KEV listing. Until patched, stop exposing the device's web interface to the internet (remove port forwarding/DMZ rules or restrict access to trusted management networks). Because exploitation is being observed, check NAS logs for unexpected requests to system_mgr.cgi and signs of unauthorized command execution. | 9.8 | 100% | KEV PoC |
| largetens of thousands of internet-exposed DNS-320 devices (estimate; total installed base likely higher) | |
| CVE-2022-37055 | Unauthenticated Buffer Overflow in D-Link GO-RT-AC750 Router Firmware CVE-2022-37055 is a buffer overflow (CWE-120) in the cgibin binary's hnap_main handler on D-Link GO-RT-AC750 routers running GORTAC750_revA_v101b03 or GO-RT-AC750_revB_FWv200b02 firmware. Because the flaw sits in the router's HNAP/web management interface and requires no authentication, a remote attacker can trigger it with crafted network requests sent directly to the device. Successful exploitation can corrupt memory and is scored critical (CVSS 3.1: 9.8), giving the attacker potential full control of the router with high confidentiality, integrity, and availability impact. Owners of these specific GO-RT-AC750 (rev A and rev B) firmware releases are affected, and the broader context of active Mirai-family botnet campaigns targeting Linux-based edge devices raises the risk of automated mass exploitation. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-12-08, confirming exploitation in the wild, and its EPSS of 55.5% (99th percentile) indicates a high near-term probability of exploitation. Do: Check GO-RT-AC750 (rev A and rev B) devices for the listed firmware versions and apply D-Link's mitigations or updated firmware per vendor instructions; if no fixed firmware is available, discontinue use of the device. Reduce exposure immediately by disabling HNAP, blocking remote management, or restricting the router's web interface to trusted networks, since exploitation requires no credentials. Federal agencies should follow BOD 22-01 timelines for remediation. | 9.8 | 56% | KEV PoC |
| largelikely tens of thousands of internet-exposed units (public scans repeatedly find large populations of HNAP-enabled D-Link consumer routers; exact counts for… | |
| CVE-2023-52163 | Missing Authorization Enables Command Injection in Digiever DS-2105 Pro NVRs Digiever DS-2105 Pro network video recorders (firmware version 3.1.0.71-11 is cited in the advisory) expose a time_tzsetup.cgi endpoint that fails to properly enforce authorization (CWE-862), and crafted requests to it trigger operating-system command injection; the CVSS 8.8 score reflects network reachability, low privilege requirements, and no user interaction. Successful exploitation yields command execution on the device with high impact on confidentiality, integrity, and availability — effectively remote code execution, which makes these NVRs attractive targets for IoT botnets such as the RondoDox campaign and the Mirai-variant ShadowV2. Only organizations still running the DS-2105 Pro (or DS-2105 Pro+) are affected, and because the vendor no longer supports the product, unpatched internet-facing units are the primary risk. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-12-22, EPSS puts the 30-day exploitation probability at 96.9%, and ransomware use is currently unknown. Do: Because the product is end-of-life, check with Digiever for any final firmware update and apply it per vendor instructions; if no patch or mitigation is available, the CISA KEV required action is to discontinue use of the device, and federal agencies must follow BOD 22-01 timelines. In the interim, remove direct internet exposure of the NVR's web interface (restrict via firewall or place behind VPN) and hunt for compromise by looking for suspicious requests to time_tzsetup.cgi and unexpected outbound connections consistent with botnet infection. | 8.8 | 97% | KEV PoC ×3 |
| moderatelikely on the order of thousands of internet-exposed NVRs (estimated; exact install base unknown) | |
| CVE-2024-10914 +1 in the same advisory: …10915 | OS Command Injection in D-Link DNS-320/320LW/325/340L NAS Firmware CVE-2024-10914 is a critical OS command injection flaw (CWE-74/CWE-78/CWE-707) in the cgi_user_add function of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add on D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L network-attached storage devices. A remote, unauthenticated attacker can trigger it by manipulating the 'name' argument sent to that CGI endpoint, injecting operating system commands that the device executes. Successful exploitation yields arbitrary command execution on the NAS, giving the attacker control of the device — a profile attractive for follow-on actions such as botnet recruitment, consistent with recent IoT botnet activity. Affected devices are the DNS-320, DNS-320LW, DNS-325, and DNS-340L, which news reports describe as end-of-life D-Link NAS models, with all firmware up to 20241028 listed as vulnerable. A public proof-of-concept is available, the EPSS score is 96.2% (top percentile, indicating very high likelihood of exploitation within 30 days), and news headlines indicate hackers are actively targeting the flaw, though it is not yet in CISA KEV. Do: Owners of DNS-320, DNS-320LW, DNS-325, and DNS-340L devices should check D-Link's support pages for updated firmware or end-of-life guidance and apply any fix the vendor publishes. Because the flaw is reachable via /cgi-bin/account_mgr.cgi?cmd=cgi_user_add, block or restrict remote (WAN) access to the device's web management interface — and consider blocking that specific endpoint — until patched; these EOL devices may never receive an update, in which case retiring or isolating them behind a restricted network is the safest option. | 9.2 | 96% | PoC |
| large≈ tens of thousands of internet-exposed NAS devices (10k–100k range; exact counts unknown) | |
| CVE-2024-3721 | A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability. NVD description · AI analysis pending | 6.3 | 86% | — | — | ||
| CVE-2024-53375 | Authenticated command-injection RCE in TP-Link Archer routers (HomeShield) CVE-2024-53375 is an authenticated remote code execution flaw (OS command injection, CWE-78) in the 'tmp_get_sites' function of the HomeShield feature on TP-Link Archer series routers. An attacker with valid low-privileged access to the router's management interface on an adjacent network (CVSS vector AV:A/PR:L) can trigger the flaw with crafted input to that function, and the router remains exploitable even when HomeShield is not enabled. Successful exploitation yields arbitrary command execution on the device, with high impact on confidentiality, integrity, and availability. Owners of TP-Link Archer routers that ship the HomeShield functionality are in scope; a precise list of affected models and firmware versions has not been published in the available data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known so far, but EPSS assigns a 40.5% probability of exploitation within 30 days (99th percentile), and recent IoT botnet activity targeting routers raises the stakes. Do: Identify your Archer model and current firmware version on TP-Link's support site and install the latest firmware as soon as a fix is published; no fixed version numbers are confirmed in the available data. Because the flaw requires authenticated, adjacent-network access, restrict router administration to trusted LAN clients, use a strong admin password, and disable WAN-side/remote management until patched. Note that disabling HomeShield is not a mitigation, since the flaw is exploitable even when the feature is not activated. | 8.0 | 40% |
| massplausibly millions of installed Archer routers (top-selling consumer router brand; HomeShield ships on many current models) |
Full article412 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 28, 2025

ShadowV2, a new Mirai-based botnet, briefly targeted vulnerable IoT devices during October’s AWS outage, likely as a test run.
During the late-October AWS disruption, FortiGuard Labs researchers observed the Mirai-based ‘ShadowV2’ malware exploiting IoT vulnerabilities across multiple countries and industries. The botnet was active only during the outage, suggesting a test run for future attacks. ShadowV2 targets IoT devices using flaws in products from DDWRT (CVE-2009-2765), D-Link (CVE-2020-25506, CVE-2022-37055, CVE-2024-10914, CVE-2024-10915), DigiEver (CVE-2023-52163), TBK (CVE-2024-3721), TP-Link (CVE-2024-53375).
The bot targeted devices in multiple countries worldwide, including:
- Oceania: Australia
- America: Canada, United States, Mexico, Brazil, Bolivia, Chile
- Europe: United Kingdom, Netherlands, Belgium, France, Czechia, Austria, Italy, Croatia, Greece
- Africa: Morocco, Egypt, South Africa
- Asia: Turkey, Saudi Arabia, Russia, Kazakhstan, China, Thailand, Japan, Taiwan, Philippines
Fortinet reported victims in multiple industries, including technology, retail and hospitality, manufacturing, managed security services providers, government, telecommunication and carrier services, and education.
ShadowV2 spreads through multiple IoT vulnerabilities, dropping the downloader script binary.sh from 81[.]88[.]18[.]108.

The malware resembles the Mirai LZRD variant, decoding its configuration with XOR key 0x22 and loading paths, headers, and User-Agent strings. After resolving its C2 domain, it connects to 81[.]88[.]18[.]108 and identifies itself as ShadowV2 Build v1.0.0 for IoT. It then initializes a wide range of UDP, TCP, and HTTP flood methods, waits for C2 commands, and launches DDoS attacks based on received parameters.
“ShadowV2 supports two transport-layer protocols (UDP and TCP) and the HTTP application protocol. Implemented attack methods including UDP floods, several TCP-based floods, and HTTP-level floods. The malware maps these behaviors to internal function names, such as UDP, UDP Plain, UDP Generic, UDP Custom, TCP, TCP SYN, TCP Generic, TCP ACK, TCP ACK STOMP, and HTTP.” reads the report published by Fortinet. “It listens for commands from its C2 server and triggers DDoS attacks using the corresponding attack method ID and parameters.”
ShadowV2 shows that IoT devices are still a major security weak point. Its evolution signals that threat actors are increasingly focusing on IoT environments.
“The evolution of ShadowV2 suggests a strategic shift in the targeting behavior of threat actors toward IoT environments.” concludes the report. “This underscores the importance of maintaining timely firmware updates, enforcing robust security practices, and continuously monitoring relevant threat intelligence to strengthen overall situational awareness and ensure ecosystem resilience.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, ShadowV2 botnet)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185135/malware/new-mirai-variant-shadowv2-tests-iot-exploits-amid-aws-disruption.html