Newly identified botnet targets decade-old flaw in unpatched D
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2015-2051 | Remote Command Execution via HNAP GetDeviceSettings in D-Link DIR-645 Router The D-Link DIR-645 wired/wireless router is vulnerable to OS command injection (CWE-77) in its HNAP interface: input supplied to the GetDeviceSettings action is not properly neutralized, so a remote attacker who sends a crafted HTTP request to the router's HNAP endpoint can have arbitrary operating-system commands executed on the device. Successful exploitation gives the attacker control of the router at the system level, enabling reconfiguration or abuse of the device, traffic interception or redirection, and recruitment into IoT botnets, as reflected in recent Moobot/MooBot botnet campaigns. Any site or household still running a DIR-645, especially one whose web/HNAP management interface is reachable from the internet, is affected; the product is end-of-life. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS assigns a 97.1% probability of exploitation within 30 days (100th percentile). CISA's required action reflects the risk: disconnect the impacted product if it is still in use because it has reached end-of-life. Do: Because the DIR-645 is end-of-life, CISA's required action is to disconnect it; replace the device where possible, or at minimum apply the latest available D-Link firmware for the DIR-645 and ensure the management/HNAP interface is not reachable from the internet (block or restrict remote administration on the WAN side). Check the device for signs of botnet infection, such as unexpected outbound traffic or unexpected HNAP POST/SOAP requests, and prioritize this fix given the 97.1% EPSS score and known in-the-wild exploitation. | — | 97% | KEV |
| largetens of thousands of internet-exposed devices (est.; far more DIR-645 units exist behind NAT given the product's broad consumer/SOHO distribution) | |
| CVE-2024-3273 +1 in the same advisory: …3272 | Command Injection in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L NAS Devices D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L network-attached storage devices contain a command injection flaw (CWE-77) in which attacker-controlled input is passed to an underlying system shell. The flaw can be triggered remotely, and when chained with the related CVE-2024-3272 it allows an unauthenticated attacker to execute arbitrary commands on the device without credentials. Successful exploitation gives an attacker full control over the affected NAS, providing a foothold for data theft, malware deployment, or further network compromise. Users of these legacy D-Link NAS models are affected; all hardware revisions of these products have reached end-of-life or end-of-service, so no routine security updates are being delivered through the normal lifecycle. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, indicating exploitation in the wild, with a very high EPSS probability of near-term exploitation. Do: Because these devices are EOL/EOS, retire and replace them per D-Link's lifecycle guidance rather than waiting for a patch; check vendor channels for any interim firmware releases. As an interim mitigation, disconnect these NAS devices from direct internet access or restrict access via firewall rules, and review device/web server logs for suspicious requests indicating command injection attempts. | 9.8 | 100% | KEV PoC |
| largeon the order of tens of thousands of internet-exposed D-Link NAS devices (estimated, not confirmed by the supplied data) |
Full article282 words · extracted from therecord.media · click to collapse
Researchers have discovered a new botnet, labeled Goldoon, that exploits a decade-old vulnerability in unpatched D-Link routers. The flaw — CVE-2015-2051 — “presents a low attack complexity,” but has a critical security impact that can allow intruders to run code remotely on infected hardware, according to a report from cybersecurity firm Fortinet. “Once attackers successfully exploit this vulnerability, they can incorporate compromised devices into their botnet to launch further attacks,” Fortinet said. The researchers named the botnet after an element called goldoon.server within malware that spreads it. Goldoon can record information about the targeted system and is leveraged by hackers to launch distributed denial-of-service (DDoS) attacks — a classic use for botnets. According to researchers, the botnet’s activity spiked in April, “almost doubling the usual frequency.” D-Link patched the flaw as part of a firmware update in the first half of 2015. Unpatched D-Link hardware has drawn attention recently from researchers as well as the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The agency said earlier in April that some older D-Link devices are being exploited by threat actors. In particular, CISA added CVE-2024-3273 and CVE-2024-3272 to its Known Exploited Vulnerabilities list, giving federal agencies a short window to retire or replace D-Link hardware that in some cases could be a decade old. Products from other companies can have similar problems. Fortinet previously reported that botnets continue to exploit a year-old vulnerability in unpatched TP-Link internet routers. Upon the discovery of Goldoon, Fortinet stated that seeing hackers exploit old bugs "reminds us that botnets continue to evolve and exploit as many devices as possible." Researchers recommended applying patches and updates “whenever possible” because of the ongoing development and introduction of new botnets.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/goldoon-botnet-unpatched-dlink-routers