ZeroHour
Security Affairspublished ()ingested @securityaffairs

New Mirai botnet variant appears in the threat landscape

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-19356
Command Injection RCE as Root in Netis WF2419 Routers

Netis WF2419 routers contain an operating-system command injection flaw (CWE-78) in the router's web management page that allows an attacker to execute arbitrary commands with root privileges. The flaw is triggered through the web management interface, where crafted input is passed to a system command without adequate sanitization, enabling unauthenticated or low-privilege access to escalate to full command execution as root. An attacker who exploits it gains complete control of the router — root-level code execution — which can be used to intercept or manipulate traffic, pivot into the local network, or enlist the device in a botnet. Any user or organization running a Netis WF2419 router is affected, with the greatest risk on devices whose web management page is reachable from the WAN/internet. Although no public proof-of-concept is known and no CVSS score is published, CISA added the issue to the Known Exploited Vulnerabilities catalog on 2021-11-03 (confirming in-the-wild exploitation; ransomware use not reported), and the 98th-percentile EPSS of 28.2% indicates an elevated probability of exploitation over the next 30 days.

Do: Upgrade WF2419 firmware to the latest release from Netis per the vendor's instructions, as required by CISA (no specific fixed firmware version is provided in this data — check with Netis). Disable or restrict WAN-side remote administration so the web management page is not reachable from the internet, and review device logs for signs of exploitation or compromise. Given the KEV listing and 98th-percentile EPSS despite the missing CVSS score, treat this as a high-priority patch for any WF2419 units in service.

7.528% KEV PoC ×3
  • Netis WF2419 router (WF2419 Devices)
mass≈1–2 million+ deployed devices worldwide, with likely on the order of 100,000+ internet-exposed (estimate)
CVE-2020-25506
Command Injection in D-Link DNS-320 system_mgr.cgi Allows Remote Code Execution

CVE-2020-25506 is an operating system command injection flaw (CWE-78) in the system_mgr.cgi component of D-Link DNS-320 network-attached storage devices. An attacker can trigger it by sending crafted input to the system_mgr.cgi handler of the device's web management interface, causing attacker-controlled data to be executed as operating system commands. Successful exploitation may allow remote code execution on the NAS, giving an attacker control over the device and its stored data. Any D-Link DNS-320 running affected firmware is at risk; the available data does not specify affected or fixed version ranges. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and current EPSS assigns roughly a 100% probability of exploitation within 30 days, though a specific ransomware association has not been confirmed.

Do: Apply D-Link firmware updates for the DNS-320 per the vendor's instructions, as required by CISA's KEV listing. Until patched, stop exposing the device's web interface to the internet (remove port forwarding/DMZ rules or restrict access to trusted management networks). Because exploitation is being observed, check NAS logs for unexpected requests to system_mgr.cgi and signs of unauthorized command execution.

9.8100% KEV PoC
  • D-Link DNS-320 (network-attached storage device)
largetens of thousands of internet-exposed DNS-320 devices (estimate; total installed base likely higher)
CVE-2020-26919
Missing Function-Level Access Control in NETGEAR JGS516PE Smart Managed Switches

CVE-2020-26919 is a missing function-level access control flaw in NETGEAR JGS516PE ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switches running firmware before 2.6.0.43. An unauthenticated remote attacker can invoke privileged switch functions over the network without authorization, consistent with the CVSS 9.8 critical score (network vector, no privileges or user interaction required). Successful exploitation grants the attacker full functional control of the switch's management functions, with high impact on confidentiality, integrity, and availability of the device. Any organization or site running a JGS516PE switch on affected firmware is exposed, particularly where the management interface is reachable from untrusted networks. The flaw is listed in the CISA Known Exploited Vulnerability Catalog (added 2021-11-03), indicating it is known to be exploited in the wild, and related reporting on Mirai variants targeting network devices suggests active scanning and botnet interest in this class of equipment.

Do: Upgrade JGS516PE switch firmware to version 2.6.0.43 or later per NETGEAR's instructions, as required by the CISA KEV listing. Restrict the switch's management interface (web and network management protocols) to trusted management VLANs or administrative networks and avoid internet exposure. Check whether the device appears in KEV-driven scanning activity and monitor for Mirai-style botnet targeting of network infrastructure.

9.857% KEV
  • NETGEAR JGS516PE firmware (ProSAFE 16-port Gigabit PoE+ Smart Managed Plus switch) All firmware versions before 2.6.0.43
largeon the order of tens of thousands of deployed JGS516PE switches, with a likely lower but non-trivial subset (thousands to tens of thousands) having management…
CVE-2021-22502
Unauthenticated Command Injection RCE in Micro Focus Operation Bridge Reporter

CVE-2021-22502 is an unauthenticated OS command injection flaw (CWE-78) in Micro Focus Operation Bridge Reporter (OBR) version 10.40, rated critical (CVSS 9.8) because it is reachable over the network with no privileges or user interaction required. By sending crafted input to the exposed OBR service, an attacker can inject operating-system commands that are executed directly on the OBR server. Successful exploitation yields full remote code execution with the privileges of the affected service, giving attackers a foothold in enterprise IT operations environments. Organizations running OBR 10.40 — an enterprise IT-operations analytics/reporting server — are affected, particularly where the OBR interface is reachable from untrusted networks. Exploitation status is high-concern: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, a public proof-of-concept for unauthenticated command injection exists, and EPSS puts the 30-day exploitation probability at 96.7% (top percentile).

Do: Apply the vendor update for Operation Bridge Reporter per Micro Focus/OpenText instructions, as required by the CISA KEV catalog; confirm the deployed OBR build resolves 10.40. Until patched, restrict network access to the OBR server (firewall rules, VPN-only access) and hunt for signs of compromise such as unexpected processes, suspicious outbound connections, or web-shell artifacts on the server.

9.897% KEV PoC
  • Micro Focus Operation Bridge Reporter (OBR) 10.40
moderatelikely on the order of thousands of enterprise deployments worldwide (roughly 1,000–10,000 systems), with only a fraction internet-exposed; exact counts unknown
CVE-2021-27561
Unauthenticated Root Command Injection in Yealink Device Management

CVE-2021-27561 is a critical (CVSS 9.8) unauthenticated OS command injection flaw (CWE-78) in Yealink Device Management (DM) 3.6.0.20, which CISA also characterizes as a server-side request forgery issue. A remote attacker can send a crafted, unauthenticated HTTP request to the /sm/api/v1/firewall/zone/services URI to inject operating system commands that execute with root privileges on the DM server. Successful exploitation yields full root control of the management server, allowing an attacker to pivot into the managed VoIP/UC environment, move laterally inside the network, or enroll the host in an IoT-style botnet. The flaw affects organizations running Yealink Device Management to administer fleets of Yealink IP phones, and it is trivially exploitable over the network with no user interaction. It was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, and the recent emergence of Mirai-variant botnets targeting network devices is consistent with active mass-scanning for this class of unauthenticated injection flaw; EPSS puts the 30-day exploitation probability at roughly 83%.

Do: Upgrade Yealink Device Management to a fixed release per Yealink's instructions (the confirmed affected version is 3.6.0.20); CISA's required action is to apply vendor updates. Until patched, restrict access to the DM web interface to trusted management networks and verify it is not internet-exposed. Check access logs for unauthenticated requests to /sm/api/v1/firewall/zone/services, which would indicate probing or exploitation.

9.883% KEV
  • Yealink Device Management 3.6.0.20 confirmed affected (command injection as root); other/prior versions not specified in the source data
moderatethousands (order of magnitude 1k–10k) of deployed DM servers, many internet-exposed
CVE-2021-27562
Out-of-Bounds Write in Arm Trusted Firmware-M Through 1.2

Arm Trusted Firmware-M (TF-M), the open-source reference secure firmware for Cortex-M microcontrollers with TrustZone, through version 1.2 contains an out-of-bounds write (CWE-787) in the non-secure processing environment (NSPE) handler-mode path. The flaw is triggered when software running in the non-secure world calls a secure function while in handler mode, which can corrupt memory or secure state. A successful trigger can halt the system, overwrite secure data, or print secure data to output; the scored impact is high availability (CVSS 3.1: 5.5, AV:L/PR:L), so exploitation requires local code execution in the non-secure world. Any device whose firmware is built on TF-M 1.2 or earlier is affected, spanning the many silicon vendors and IoT products that ship Arm's reference secure firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known exploitation in the wild, though no public PoC is documented and ransomware use is unknown.

Do: Apply updates per vendor instructions: device makers and OEMs should rebuild firmware on a TF-M release newer than 1.2, and device owners should install updated firmware/SDKs from their silicon vendor or OEM. Check which of your microcontroller-based products (e.g., IoT endpoints) use Trusted Firmware-M and whether they run third-party or non-secure applications that could invoke secure functions; because exploitation requires local code execution, prioritize devices accepting remote code or app deployment. Containment is not otherwise available, as the fix is in the secure firmware itself.

5.53% KEV
  • trustedfirmware (Arm Trusted Firmware-M project) Trusted Firmware-M through 1.2 (all versions up to and including 1.2)
masspotentially millions of embedded/IoT devices built on TF-M 1.2 or earlier (no public install counts; broad but unquantified)
Full article361 words · extracted from securityaffairs.com · click to collapse

Palo Alto researchers uncovered a series of ongoing attacks to spread a variant of the infamous Mirai bot exploiting multiple vulnerabilities.

Security experts at Palo Alto Networks disclosed a series of attacks aimed at delivering a Mirai variant leveraging multiple vulnerabilities.

Below the list of vulnerabilities exploited in the attacks, three of which were unknown issues:

IDVulnerabilityDescriptionSeverity
1VisualDoorSonicWall SSL-VPN Remote Command Injection VulnerabilityCritical
2CVE-2020-25506D-Link DNS-320 Firewall Remote Command Execution VulnerabilityCritical
3CVE-2021-27561 and CVE-2021-27562Yealink Device Management Pre-Auth ‘root’ Level Remote Code Execution VulnerabilityCritical
4CVE-2021-22502Remote Code Execution Vulnerability in Micro Focus Operation Bridge Reporter (OBR), affecting version 10.40Critical
5CVE-2019-19356Resembles the Netis WF2419 Wireless Router Remote Code Execution VulnerabilityHigh
6CVE-2020-26919Netgear ProSAFE Plus Unauthenticated Remote Code Execution VulnerabilityCritical
7UnidentifiedRemote Command Execution Vulnerability Against an Unknown TargetUnknown
8UnidentifiedRemote Command Execution Vulnerability Against an Unknown TargetUnknown
9Unknown VulnerabilityVulnerability Used by Moobot in the Past, Although the Exact Target is Still UnknownUnknown

“The attacks are still ongoing at the time of this writing. Upon successful exploitation, the attackers try to download a malicious shell script, which contains further infection behaviors such as downloading and executing Mirai variants and brute-forcers.” reads a post published by Palo Alto Networks’ Unit 42.

The attacks were first observed on February 16, experts noticed that upon successful exploitation, the malicious code uses the wget utility to download a shell script from the C2. The shell script downloads several Mirai binaries that were compiled for different architectures, then it executes these binaries one by one.

Mirai bot wget

Experts noticed that the malware also downloads more shell scripts that retrieve brute-forcers that could be used to target devices protected with weak passwords.

“The IoT realm remains an easily accessible target for attackers. Many vulnerabilities are very easy to exploit and could, in some cases, have catastrophic consequences,” the researchers conclude.

If you want to receive the weekly Security Affairs Newsletter for free subscribe here.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Mirai)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/115664/uncategorized/mirai-botnet-variant-2.html