ZeroHour
Security Affairspublished ()ingested @securityaffairs

Mirai-based botnets exploit CVE-2025-1316 zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-1316

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-1316
Unauthenticated OS Command Injection RCE in Edimax IC-7100 IP Camera

CVE-2025-1316 is an OS command injection flaw (CWE-78) in the Edimax IC-7100 IP camera that fails to properly neutralize requests it receives. Because the request handling is reachable over the network without authentication or user interaction (per the CVSS 4.0 vector), an unauthenticated attacker can send specially crafted requests to the device. Successful exploitation yields full remote code execution on the camera, with high impact on confidentiality, integrity, and availability of the device itself. Only deployments using the Edimax IC-7100 camera and its firmware are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, and public reporting indicates Mirai-based botnets have been exploiting it since roughly a year before its disclosure, making it effectively a zero-day used to recruit cameras into botnets.

Do: Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the IC-7100 if mitigations are unavailable; check whether Edimax has released updated firmware and install it. In the meantime, reduce exposure by removing any port-forwarding or direct internet access to affected cameras, restricting management interfaces to trusted networks, and monitoring for Mirai-like scanning or traffic. Treat exploitation as likely given the high EPSS (74.5% in 30 days) and in-the-wild botnet use.

9.374% KEV
  • Edimax IC-7100 IP Camera firmware
moderateapproximately 1,000-10,000 internet-exposed devices (estimated)
Full article296 words · extracted from securityaffairs.com · click to collapse

Mirai-based botnets are exploiting a zero-day flaw, tracked as CVE-2025-1316, in Edimax IP cameras, to achieve remote command execution.

US CISA warns that multiple botnets are exploiting a recently disclosed vulnerability, tracked as CVE-2025-1316 (CVSS score of 9.8), in Edimax IC-7100 IP cameras.

The issue is an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’.

Edimax IC-7100 fails to properly sanitize requests, an attacker can create specially crafted requests to achieve remote code execution on the device. Report suspected malicious activity to CISA for tracking and correlation with other incidents.

“Successful exploitation of this vulnerability could allow an attacker to send specially crafted requests to achieve remote code execution on the device.” reads the advisory published by CISA. “Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.”

The flaw impacts all C-7100 IP Camera versions and has yet to address the vulnerability because these cameras are end-of-life products.

The advisory doesn’t confirm exploitation of the flaw in the wild, however, the USE agency urges organizations to report suspected malicious activity for tracking and correlation.

Akamai researchers discovered the vulnerability, and the cyber security firm confirmed ([1],[2]) that the flaw is actively exploited in the wild.

The experts observed multiple Mirai-based botnets that are currently exploiting multiple flaws, including Edimax IC-7100 IP cameras.

Threat actors exploit remote command execution to run a shell script that downloads a Mirai malware payload from a remote server.

The vendor, notified in Oct 2024, has been unresponsive to CISA and Akamai. Akamai warns that the vulnerability may affect supported ones.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, US CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/175060/hacking/mirai-based-botnets-exploit-cve-2025-1316-zero-day-in-edimax-ip-cameras.html