ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

AI summary · glm-5.3-flash

Fortinet researchers documented Evooo1Bot, a new Mirai-derived Linux botnet active since July 2026 that exploits known edge-device flaws to build SOCKS5 proxy networks.

Fortinet FortiGuard Labs identified Evooo1Bot, a previously undocumented Linux botnet built on the leaked Mirai source code, active in the wild since July 2026 and targeting internet-facing edge devices. It exploits numerous known CVEs in routers and devices from D-Link, Tenda, Telesquare, Zyxel, Hikvision, Atlassian Confluence, WSO2, TP-Link, NETGEAR, and others, delivering a bot binary via a wget.sh loader from 91.92.40.118 that clears bash history. The bot offers encrypted C2 on port 443, SSH brute-force scanning, credential sniffing, DDoS over DNS/TCP/UDP, an HTTP exploit dispatcher, and converts infected hosts into SOCKS5 proxies for anonymizing follow-on operations.

  • Derived from leaked Mirai source code, extended with encrypted C2, SSH brute-force scanner, and SOCKS relay module
  • Exploits known CVEs in D-Link, Tenda, Telesquare, Zyxel, Hikvision, Confluence, WSO2, TP-Link, and more
  • Turns routers, firewalls, and cameras into SOCKS5 proxies to disguise traffic and reach internal networks
  • Loader script wipes bash history; binary checks for sandboxes and blends C2 into HTTPS on port 443
  • Supports DDoS attacks over DNS, TCP, and UDP plus persistence, file transfer, and interactive shell commands

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2007-3010
Command Injection RCE in Alcatel OmniPCX Enterprise masterCGI

CVE-2007-3010 is a command execution flaw in masterCGI, a component of the Unified Maintenance Tool in the Alcatel OmniPCX Enterprise Communication Server. Because the CGI fails to properly validate user-supplied input (CWE-20), a remote attacker can send crafted requests to the web-based maintenance interface and inject arbitrary operating system commands, which are executed on the PBX server. Successful exploitation yields remote code execution on the communication server, giving attackers a foothold on a Linux-based edge device that could be used for further compromise, lateral movement into the voice network, or, per recent botnet trends, conscription into proxy botnets. Any organization running an Alcatel OmniPCX Enterprise communication server with the Unified Maintenance Tool reachable is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) with a very high 97.4% EPSS score, indicating active in-the-wild exploitation, though no public proof-of-concept code is known.

Do: Apply updates per vendor instructions (Alcatel/Aastra/Alcatel-Lucent Enterprise maintenance releases) as required by CISA's KEV catalog. Until patched, restrict access to the Unified Maintenance Tool web interface (masterCGI) to trusted management networks only, e.g., via firewall or ACL rules, and avoid exposing it to the internet. Given recent Mirai-based botnets targeting Linux edge devices, audit OmniPCX servers for signs of compromise such as unexpected processes or outbound proxy (SOCKS5) traffic.

97% KEV
  • Alcatel OmniPCX Enterprise Communication Server (Unified Maintenance Tool / masterCGI)
moderateroughly 1,000–10,000 internet-exposed systems (estimate; enterprise PBX deployments with only a fraction exposing the management interface)
CVE-2016-6277
Unauthenticated RCE via Command Injection in NETGEAR Multiple Routers

Multiple NETGEAR router models allow unauthenticated web pages to pass form input directly to the device's command-line interface, which permits remote code execution (CVE-2016-6277). An attacker triggers the flaw by sending a crafted HTTP request to the router's web interface without logging in, causing attacker-supplied input to be interpreted as commands on the router. Successful exploitation grants the ability to run arbitrary commands on the device, typically with root privileges, enabling full takeover of the router and use as a pivot point into the network behind it. Any NETGEAR router among the affected models running firmware without the vendor patch is vulnerable, with internet-facing management interfaces at greatest risk. The flaw was added to CISA's Known Exploited Vulnerability catalog on 2022-03-07, indicating exploitation in the wild, and it carries a very high 99.8% EPSS probability of exploitation within 30 days.

Do: Update affected NETGEAR routers to the latest available firmware for the specific model, per the vendor's upgrade instructions, as required by CISA's KEV listing. As interim mitigation, disable WAN-side/remote management and restrict the router's admin interface to the local network, then review devices for signs of compromise such as unexpected configuration changes or added accounts.

8.8100% KEV PoC ×3
  • NETGEAR
masslikely 100,000+ internet-exposed NETGEAR routers (exact count unknown)
CVE-2018-14558
Unauthenticated Command Injection in Tenda AC7, AC9, and AC10 Routers

CVE-2018-14558 is an unauthenticated OS command injection flaw (CWE-78) in the web interface of Tenda AC7, AC9, and AC10 routers, where the formsetUsbUnload handler passes untrusted input to the dosystemCmd function. An attacker triggers it by sending a crafted HTTP request to the goform/setUsbUnload endpoint, requiring no authentication or user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields arbitrary command execution on the router, enabling full device takeover for traffic interception, botnet enrollment, or pivoting into the local network. Anyone running AC7 firmware through V15.03.06.44_CN(AC7), AC9 firmware through V15.03.05.19(6318)_CN(AC9), or AC10 firmware through V15.03.06.23_CN(AC10) is affected. The flaw has a public proof of concept, an 8.7% EPSS (95th percentile), and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating exploitation in the wild.

Do: Apply updated firmware from Tenda per vendor/CISA instructions, upgrading AC7 beyond V15.03.06.44_CN, AC9 beyond V15.03.05.19(6318)_CN, and AC10 beyond V15.03.06.23_CN. Until patched, avoid exposing the router's web management interface to the internet (disable remote/WAN management) and restrict admin access to trusted clients. Check device logs for unsolicited requests to goform/setUsbUnload as an indicator of exploitation.

9.89% KEV PoC
  • Tenda AC7 router firmware through V15.03.06.44_CN(AC7)
  • Tenda AC9 router firmware through V15.03.05.19(6318)_CN(AC9)
  • Tenda AC10 router firmware through V15.03.06.23_CN(AC10)
massplausibly 1M+ affected devices (estimate; hundreds of thousands of Tenda web interfaces appear internet-exposed in public scans)
CVE-2019-14931
An issue was discovered on Mitsubishi Electric Europe B.V.

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

NVD description · AI analysis pending
9.858% PoC
  • mitsubishielectric smartrtu firmware
  • mitsubishielectric me-rtu firmware
CVE-2020-10987
Unauthenticated OS Command Injection in Tenda AC15 AC1900 Router

CVE-2020-10987 is an unauthenticated OS command injection flaw (CWE-78) in the goform/setUsbUnload endpoint of the Tenda AC15 AC1900 router, demonstrated on firmware version 15.03.05.19. An attacker triggers it by sending a crafted deviceName POST parameter to that endpoint, which is not properly sanitized before being used in a system command. Successful exploitation yields arbitrary remote code execution on the router, giving the attacker full control of the device and a foothold to pivot into the local network, as is typical for IoT botnet recruitment. Owners of Tenda AC15 routers are affected, with greatest risk on units whose web administration interface is reachable from the internet. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 79.8% EPSS score (top percentile), and a public proof of concept has been available since its 2020 disclosure; ransomware use is unknown.

Do: Apply the latest Tenda AC15 firmware available from the vendor (newer than 15.03.05.19) per CISA's required action and vendor instructions. Until patched, disable or restrict WAN-side remote web administration to trusted source IPs, since the flaw is exploitable without credentials over the network. Check router HTTP logs for unexpected POST requests to /goform/setUsbUnload containing suspicious deviceName values, and monitor for botnet-style command activity.

9.880% KEV PoC
  • Tenda AC15 AC1900 router firmware Firmware version 15.03.05.19 (the only version named in the advisory; the full affected version range is not specified, so other AC15 firmware releases may also
moderateLikely on the order of thousands to tens of thousands of remotely exploitable Tenda AC15 units (estimate; no authoritative install-base or scan count provided).
CVE-2021-36260
Unauthenticated Command Injection in Hikvision Device Web Server

CVE-2021-36260 is a command injection flaw (CWE-78) in the web server embedded in a wide range of Hikvision security camera and related devices, caused by insufficient input validation. An attacker triggers it by sending a crafted HTTP request to the device's web management interface, allowing commands to be executed on the device without authentication. Successful exploitation grants unauthenticated remote code execution on the camera or recorder, letting an attacker take control of the device, pivot into the surrounding network, or use the devices as a botnet platform. Any Hikvision device running the affected web server firmware is at risk, which includes cameras, recorders, and other surveillance hardware deployed in homes, businesses, and government facilities. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 and carries a 99.9% EPSS probability of exploitation within 30 days, while no public proof-of-concept code is cataloged in the provided data and no CVSS score has been issued yet.

Do: Apply firmware updates issued by Hikvision per the vendor's instructions, as required by CISA's KEV listing for this vulnerability. Restrict the device web management interface to trusted networks or VPN access and avoid direct internet exposure. Review web server logs for anomalous HTTP requests to the device interface and signs of command execution, and prioritize internet-facing devices for patching first.

9.8100% KEV PoC ×3
  • Hikvision Embedded web server of Hikvision security cameras and related surveillance devices
massmillions of installed devices, with roughly hundreds of thousands to over a million Hikvision web interfaces exposed to the internet
CVE-2021-46422
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

NVD description · AI analysis pending
9.894% PoC ×2
  • telesquare sdt-cs3b1 firmware
CVE-2022-26134
Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center

Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target.

Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections.

9.8100% KEV ransomware PoC ×2
  • Atlassian Confluence Server
  • Atlassian Confluence Data Center
largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022…
CVE-2022-29464
Unrestricted file upload leading to unauthenticated RCE in multiple WSO2 products

CVE-2022-29464 is an unrestricted file upload flaw (CISA classifies it as CWE-22, path traversal) in multiple WSO2 products — including WSO2 API Manager, Identity Server (and its Analytics and as-Key-Manager variants), and Enterprise Integrator — that lets an attacker write arbitrary files, such as JSP webshells, to any location on the server. It is triggered by sending crafted multipart upload requests to the WSO2 Carbon management-console file-upload endpoints, where directory traversal in the upload path allows files to be planted in the web root; requesting the uploaded file then executes it as code. An attacker who can reach a vulnerable management console gains unauthenticated remote code execution with the privileges of the WSO2 server process, which is often root in containerized deployments, enabling webshells, lateral movement, and ransomware staging. Any organization running affected WSO2 releases is exposed, especially where Identity Server (SSO/IAM) or API Manager gateways are internet-facing; the exact affected version ranges are enumerated in the WSO2 vendor advisory. Exploitation is confirmed: CISA added the flaw to the KEV catalog on 2022-04-25 with known ransomware use, and EPSS assigns a roughly 100% probability of exploitation within 30 days, making patching urgent.

Do: Apply the WSO2 updates/patches listed in the WSO2 security advisory for CVE-2022-29464 (or upgrade to the fixed releases named there), per CISA's required action, and limit internet exposure of Carbon management consoles in the meantime. Because ransomware groups have exploited this flaw, hunt for compromise: check web roots for unexpected JSP files or webshells and review access logs for suspicious file-upload requests followed by GETs to uploaded files.

9.8100% KEV ransomware PoC ×2
  • WSO2
largeon the order of tens of thousands of internet-exposed WSO2 management consoles (roughly 10,000–100,000 systems); total deployments including internal installs…
CVE-2022-30525
OS Command Injection in Zyxel Firewalls Enables Remote Command Execution

CVE-2022-30525 is an OS command injection vulnerability (CWE-78) in the CGI program of certain Zyxel firewall firmware versions. By sending crafted requests to the vulnerable CGI program, an attacker can modify specific files on the appliance and inject and execute operating system commands. Successful exploitation yields command execution on the firewall itself, allowing an attacker to alter device files/configuration and potentially pivot into the protected network — the class of edge-device flaw commonly targeted by ransomware operators (ransomware use in this case is not yet confirmed). Organizations running affected Zyxel firewalls, particularly those with management interfaces reachable from the internet, are at risk. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-05-16, EPSS assigns a 99.9% 30-day exploitation probability (100th percentile), and no public PoC is catalogued yet.

Do: Apply Zyxel's fixed firmware per the vendor's instructions immediately, as required by the CISA KEV listing. Until patched, restrict HTTP/HTTPS management access to the firewall to trusted source addresses only. Because exploitation is confirmed in the wild, prioritize internet-facing Zyxel firewalls and review devices for indicators of compromise such as modified configurations or unexpected administrative changes.

9.8100% KEV PoC ×3
  • Zyxel Multiple firewall firmware versions; exact affected version ranges per Zyxel's advisory (not enumerated in source data)
large≈ tens of thousands of internet-exposed Zyxel firewall management interfaces (order of magnitude 10k–100k devices)
CVE-2022-37055
Unauthenticated Buffer Overflow in D-Link GO-RT-AC750 Router Firmware

CVE-2022-37055 is a buffer overflow (CWE-120) in the cgibin binary's hnap_main handler on D-Link GO-RT-AC750 routers running GORTAC750_revA_v101b03 or GO-RT-AC750_revB_FWv200b02 firmware. Because the flaw sits in the router's HNAP/web management interface and requires no authentication, a remote attacker can trigger it with crafted network requests sent directly to the device. Successful exploitation can corrupt memory and is scored critical (CVSS 3.1: 9.8), giving the attacker potential full control of the router with high confidentiality, integrity, and availability impact. Owners of these specific GO-RT-AC750 (rev A and rev B) firmware releases are affected, and the broader context of active Mirai-family botnet campaigns targeting Linux-based edge devices raises the risk of automated mass exploitation. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-12-08, confirming exploitation in the wild, and its EPSS of 55.5% (99th percentile) indicates a high near-term probability of exploitation.

Do: Check GO-RT-AC750 (rev A and rev B) devices for the listed firmware versions and apply D-Link's mitigations or updated firmware per vendor instructions; if no fixed firmware is available, discontinue use of the device. Reduce exposure immediately by disabling HNAP, blocking remote management, or restricting the router's web interface to trusted networks, since exploitation requires no credentials. Federal agencies should follow BOD 22-01 timelines for remediation.

9.856% KEV PoC
  • D-Link GO-RT-AC750 (rev A) router firmware GORTAC750_revA_v101b03
  • D-Link GO-RT-AC750 (rev B) router firmware GO-RT-AC750_revB_FWv200b02
largelikely tens of thousands of internet-exposed units (public scans repeatedly find large populations of HNAP-enabled D-Link consumer routers; exact counts for…
CVE-2023-1389
Command Injection in TP-Link Archer AX21 Router Allows Remote Code Execution

CVE-2023-1389 is a command injection flaw (CWE-77) in TP-Link's Archer AX21 Wi-Fi 6 router that lets an attacker execute arbitrary operating-system commands on the device. It is triggered by sending crafted input to a remotely reachable service on the router, which passes attacker-controlled values to the device's shell without proper sanitization; the source data does not specify the vulnerable endpoint or exact affected firmware ranges. Successful exploitation yields remote code execution on the router, giving the attacker a foothold in the network where the router sits, from which they can pivot or abuse the device further. Any household or organization running an Archer AX21 router is affected, with the highest risk where the router's management interface is exposed to the internet. The flaw was added to CISA's KEV catalog on 2023-05-01, confirming exploitation in the wild; EPSS assigns a ~100% probability of exploitation within 30 days (top percentile), while no public proof-of-concept or ransomware association is documented in the source data.

Do: Update the Archer AX21 to the latest firmware available from TP-Link per the vendor's instructions (fixed firmware is published on the product's TP-Link support page). If updating is not immediately possible, disable WAN-side/remote management and restrict the router's web interface to the local network. Because exploitation is confirmed in the wild, also review exposed routers for signs of compromise, such as unexplained configuration changes or unexpected outbound traffic.

8.8100% KEV PoC ×2
  • TP-Link Archer AX21 (Archer AX-21) Wi-Fi 6 router
masslikely hundreds of thousands of routers deployed, with >100k plausibly internet-exposed
CVE-2024-10914
OS Command Injection in D-Link DNS-320/320LW/325/340L NAS Firmware

CVE-2024-10914 is a critical OS command injection flaw (CWE-74/CWE-78/CWE-707) in the cgi_user_add function of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add on D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L network-attached storage devices. A remote, unauthenticated attacker can trigger it by manipulating the 'name' argument sent to that CGI endpoint, injecting operating system commands that the device executes. Successful exploitation yields arbitrary command execution on the NAS, giving the attacker control of the device — a profile attractive for follow-on actions such as botnet recruitment, consistent with recent IoT botnet activity. Affected devices are the DNS-320, DNS-320LW, DNS-325, and DNS-340L, which news reports describe as end-of-life D-Link NAS models, with all firmware up to 20241028 listed as vulnerable. A public proof-of-concept is available, the EPSS score is 96.2% (top percentile, indicating very high likelihood of exploitation within 30 days), and news headlines indicate hackers are actively targeting the flaw, though it is not yet in CISA KEV.

Do: Owners of DNS-320, DNS-320LW, DNS-325, and DNS-340L devices should check D-Link's support pages for updated firmware or end-of-life guidance and apply any fix the vendor publishes. Because the flaw is reachable via /cgi-bin/account_mgr.cgi?cmd=cgi_user_add, block or restrict remote (WAN) access to the device's web management interface — and consider blocking that specific endpoint — until patched; these EOL devices may never receive an update, in which case retiring or isolating them behind a restricted network is the safest option.

9.296% PoC
  • D-Link DNS-320 firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-320LW firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-325 firmware up to and including 20241028 (all listed firmware)
  • +1 more
large≈ tens of thousands of internet-exposed NAS devices (10k–100k range; exact counts unknown)
CVE-2024-29269
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

NVD description · AI analysis pending
8.86% PoC
  • telesquare tlr-2005ksh firmware
CVE-2024-4577
OS Command Injection in Windows PHP-CGI Allows Remote Code Execution

CVE-2024-4577 is an OS command injection flaw (CWE-78) in Windows-based PHP when it runs in CGI mode, allowing arbitrary code execution on the server. It is triggered when attacker-supplied characters in HTTP requests are mishandled by Windows' character-encoding conversion as the OS invokes php-cgi, letting attackers inject command-line arguments to the PHP interpreter; this bypasses the decade-old fix for CVE-2012-1823. A successful attacker gains the ability to run arbitrary commands and code in the context of the web server. Affected systems are PHP running on Windows through the CGI interface; deployments that do not use PHP-CGI on Windows are not described as affected in the source data. Exploitation is active: the flaw was added to CISA KEV on 2024-06-12 with known ransomware use, and EPSS assigns roughly 100% probability of exploitation within 30 days.

Do: Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use: upgrade Windows PHP-CGI deployments to a PHP release that fixes CVE-2024-4577 per PHP Group advisories, or stop using CGI mode on Windows (e.g., switch to FastCGI) and apply any vendor-recommended workarounds. Given known ransomware abuse, review web server access logs for exploitation attempts (notably %AD-encoded soft hyphens and injected -d/-s arguments in php-cgi query strings) and prioritize patching internet-facing Windows hosts.

9.8100% KEV ransomware PoC ×11
  • PHP Group PHP
large≈10,000–100,000 internet-exposed Windows PHP-CGI systems
CVE-2025-10123
A vulnerability was determined in D-Link DIR-823X up to 250416.

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

NVD description · AI analysis pending
5.55% PoC ×2
  • dlink dir-823x firmware
CVE-2025-1974
Unauthenticated RCE in Kubernetes ingress-nginx controller (IngressNightmare)

CVE-2025-1974 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in the Kubernetes ingress-nginx controller, identified as part of the IngressNightmare set of defects. An attacker who has any access to the pod network, with no credentials required, can trigger the flaw and execute arbitrary code in the context of the ingress-nginx controller process. From that position the attacker can disclose Secrets accessible to the controller, and in a default installation the controller can read all Secrets cluster-wide, which follow-on coverage notes can lead to Kubernetes cluster takeover. Any Kubernetes cluster running the ingress-nginx controller is affected; public research cited in the headlines estimates the component is present in roughly 40% of cloud environments. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, but EPSS assigns a 99.5% probability of exploitation within 30 days, making urgent patching prudent.

Do: Upgrade the ingress-nginx controller to the patched release identified in the project's security advisory for CVE-2025-1974. Until patched, restrict pod-network access to the controller (including its admission webhook endpoint) so only the Kubernetes control plane can reach it, and consider narrowing the controller's RBAC so it cannot read all Secrets cluster-wide. Review audit logs for unexpected requests to the controller and inventory clusters for ingress-nginx deployments, especially internet-facing ones.

9.8100%
  • Kubernetes (ingress-nginx project) ingress-nginx controller
massvery large
CVE-2025-55583
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component.

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitization or authentication. Remote attackers can exploit this to execute arbitrary commands as root via crafted HTTP requests.

NVD description · AI analysis pending
9.87% PoC
  • dlink dir-868l firmware
Full article568 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 17, 2026Malware / Botnet

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.

"While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities," Fortinet FortiGuard Labs said.

Evidence indicates that the botnet has been active in the wild since July 2026, exploiting known vulnerabilities in publicly-accessible devices to deliver the malware. Some of the security flaws weaponized by the botnet are below -

  • CVE-2007-3010 - Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability
  • CVE-2016-6277 - NETGEAR Multiple Routers Remote Code Execution Vulnerability
  • CVE-2018-14558 - Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability
  • CVE-2019-14931 - Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability
  • CVE-2020-10987 - Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
  • CVE-2021-46422 - Telesquare SDT-CW3B1 Command Injection vulnerability
  • CVE-2022-37055 - D-Link Routers Buffer Overflow Vulnerability
  • CVE-2024-29269 - Telesquare TLR-2005KSH Command Injection Vulnerability
  • CVE-2025-10123 - D-Link DIR-823X Command Injection Vulnerability
  • CVE-2025-55583 - D-Link DIR-868L B1 router Command Injection Vulnerability

Successful exploitation leads to the execution of a loader shell script ("wget.sh") hosted on an external server ("91.92.40[.]118"), which then retrieves the botnet binary that's compatible with the device CPU architecture. The script subsequently clears Bash history to erase traces of the attack.

Upon execution, the binary checks for the presence of analysis tools, sandboxes, and virtual environments, before establishing encrypted communications with a command-and-control (C2) server on port 443. The port choice is intentional as it allows the malware to blend in with expected HTTPS traffic at the network perimeter. Once the host is registered with the C2 server, it waits for further commands to take action.

It supports a number of commands that allow an operator to install persistence mechanisms, update the binary, terminate the bot, upload/download files, launch an interactive shell, intercept HTTP Basic Authorization and Cookie headers, turn the host into a proxy node, launch an SSH brute-force scanner, trigger DDoS attacks over DNS, TCP, and UDP, and fire an HTTP-based exploit dispatcher for exploiting known flaws.

The CVE attack module includes the ability to launch exploits for eight security flaws impacting Hikvision (CVE-2021-36260), Atlassian Confluence (CVE-2022-26134), WSO2 (CVE-2022-29464), Zyxel (CVE-2022-30525), TP-Link (CVE-2023-1389), PHP (CVE-2024-4577), D-Link (CVE-2024-10914), Kubernetes (CVE-2025-1974).

The proxy component, on the other hand, transforms an infected router, firewall, IP camera, or other edge device into a SOCKS5 proxy that the threat actor can leverage as a network relay to conduct follow-on operations and evade detection.

"This capability significantly increases the value of an infected host to attackers," Fortinet said. "The victim's IP address can be used to disguise malicious traffic, bypass geographic restrictions, or provide access to internal networks through an already compromised machine."

"In larger botnets, the same functionality could also be used to build a distributed proxy infrastructure, enabling anonymous traffic forwarding or monetization through residential and enterprise proxy services."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html