New Mirai botnet targets tens of flaws in popular IoT devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-12725 | Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters. NVD description · AI analysis pending | 9.8 | 90% | PoC |
| — | |
| CVE-2019-17621 | Unauthenticated Root Command Injection in D-Link DIR-859 Router UPnP CVE-2019-17621 is an unauthenticated OS command injection flaw (CWE-78) in the UPnP endpoint /gena.cgi of D-Link DIR-859 Wi-Fi router firmware 1.05 and 1.06B01 Beta01. An attacker who can reach the UPnP service — typically by being on the local network — sends a specially crafted HTTP SUBSCRIBE request that injects and executes system commands. Because the service runs with root privileges, successful exploitation gives the attacker full control of the router, enabling configuration changes, traffic manipulation, and recruitment into botnets such as Mirai. The CISA-affected product is the DIR-859, with related D-Link DIR-series router firmware also listed in the CPE data, and public proof-of-concept references are available. The flaw is actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-29, and current headlines describe Mirai botnet campaigns leveraging it among multiple IoT flaws. Do: Apply the latest D-Link firmware updates per vendor instructions; because the DIR-859 is an older model that may no longer receive updates, CISA's required action is to discontinue use of the product if a fixed release is unavailable. If the router is not at end of life, restrict or disable UPnP where unused and ensure the UPnP endpoint is not reachable beyond the LAN, then check for signs of botnet compromise such as unusual outbound traffic or unauthorized configuration changes. | 9.8 | 90% | KEV PoC ×2 |
| large≈100k–1M deployed routers (order-of-magnitude estimate) | |
| CVE-2019-20500 | Authenticated OS Command Injection in D-Link DWL-2600AP Access Point Web Interface D-Link DWL-2600AP access points running firmware 4.2.0.15 Rev A contain an authenticated OS command injection flaw (CWE-78) in the web interface's Save Configuration function (admin.cgi?action=config_save). An attacker with valid credentials submits shell metacharacters in the configBackup or downloadServerip parameters, causing arbitrary operating-system commands to execute on the device. Successful exploitation yields command execution on the access point itself, which can be used to pivot into the local network or to conscript the device into botnets, consistent with the recently reported Mirai campaign targeting multiple IoT device flaws. Any organization still running the affected DWL-2600AP hardware is exposed, especially where the management web interface is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-29, confirming active in-the-wild exploitation, and it carries a very high EPSS (~97%) alongside a public proof-of-concept (Exploit-DB 46841). Do: Inventory all DWL-2600AP units, identify devices on the vulnerable firmware revision, and apply D-Link's latest available firmware per vendor instructions; because this product line is end-of-life, CISA's required action explicitly permits discontinuing use of the product if updates are unavailable. In the interim, restrict access to the web management interface (admin.cgi) to trusted management networks, remove any internet exposure, and ensure default or shared administrator credentials have been changed, since exploitation requires authentication. | 7.8 | 97% | KEV PoC |
| moderate≈ thousands to low tens of thousands of deployed devices worldwide (order-of-magnitude estimate; EOL product) | |
| CVE-2021-25296 | Authenticated OS Command Injection in Nagios XI 5.7.5 Windows WMI Wizard Nagios XI 5.7.5 contains an OS command injection flaw in the Windows WMI configuration wizard (windowswmi.inc.php), where authenticated user-controlled input is not properly sanitized. A single crafted HTTP request from an authenticated low-privileged user is enough to execute arbitrary operating system commands on the Nagios XI server, giving attackers full compromise of confidentiality, integrity, and availability (CVSS 8.8). Organizations running Nagios XI 5.7.5, particularly internet-facing monitoring servers, are affected. The flaw is publicly documented with proof-of-concept exploits and a Metasploit module, and it was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-01-18 with a 72.2% EPSS exploitation probability. Reported campaigns have turned vulnerable Nagios XI servers into cryptocurrency miners, and multi-exploit botnet activity (e.g., Mirai variants) has also targeted this class of flaws. Do: Upgrade Nagios XI from 5.7.5 to the latest vendor-supplied release per Nagios' instructions, as required by the CISA KEV entry. Until patched, restrict access to the Nagios XI web interface and configuration wizards and review access logs for requests to the windowswmi wizard endpoint. Also check affected servers for unexpected processes or outbound connections that could indicate cryptomining or botnet payloads. | 8.8 | 72% | KEV PoC ×3 |
| moderate≈10,000+ deployments (thousands of internet-exposed Nagios XI servers visible in public scans) | |
| CVE-2021-46422 | Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication. Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication. NVD description · AI analysis pending | 9.8 | 94% | PoC ×2 |
| — | |
| CVE-2022-27002 | Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request. NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — | |
| CVE-2022-29303 | Unauthenticated Command Injection in Contec SolarView Compact CVE-2022-29303 is an unauthenticated OS command injection flaw (CWE-78) in Contec SolarView Compact version 6.00, reachable through the conf_mail.php script. Because the CVSS vector requires no privileges and no user interaction over the network, a remote attacker can send crafted input to the vulnerable script and have it executed as operating system commands. Successful exploitation yields remote code execution on the device with the privileges of the web service, which attackers can leverage to recruit exposed monitors into Mirai-style IoT botnets or as a foothold into energy-sector networks. Affected organizations are operators of internet-facing SolarView Compact (SV-CPT-MC310 firmware) solar power monitoring systems. The flaw is under active exploitation: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-13, carries a 98% EPSS probability of exploitation within 30 days, and public reporting describes attacks threatening hundreds of solar power stations. Do: Apply Contec's updates per vendor instructions (CISA's required action), or discontinue use of the product if updates are unavailable; the affected release in the data is SolarView Compact 6.00, so update to any vendor-provided fixed release. Limit or remove internet exposure of the SolarView web interface and review access logs for unsolicited requests to conf_mail.php. Defenders should also watch for signs of IoT botnet compromise, as this flaw is among those used in Mirai campaigns. | 9.8 | 98% | KEV PoC ×2 |
| nichehundreds of internet-exposed solar power stations/monitoring systems | |
| CVE-2022-30023 | Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function. Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function. NVD description · AI analysis pending | 8.8 | 39% | PoC |
| — | |
| CVE-2022-30525 | OS Command Injection in Zyxel Firewalls Enables Remote Command Execution CVE-2022-30525 is an OS command injection vulnerability (CWE-78) in the CGI program of certain Zyxel firewall firmware versions. By sending crafted requests to the vulnerable CGI program, an attacker can modify specific files on the appliance and inject and execute operating system commands. Successful exploitation yields command execution on the firewall itself, allowing an attacker to alter device files/configuration and potentially pivot into the protected network — the class of edge-device flaw commonly targeted by ransomware operators (ransomware use in this case is not yet confirmed). Organizations running affected Zyxel firewalls, particularly those with management interfaces reachable from the internet, are at risk. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-05-16, EPSS assigns a 99.9% 30-day exploitation probability (100th percentile), and no public PoC is catalogued yet. Do: Apply Zyxel's fixed firmware per the vendor's instructions immediately, as required by the CISA KEV listing. Until patched, restrict HTTP/HTTPS management access to the firewall to trusted source addresses only. Because exploitation is confirmed in the wild, prioritize internet-facing Zyxel firewalls and review devices for indicators of compromise such as modified configurations or unexpected administrative changes. | 9.8 | 100% | KEV PoC ×3 |
| large≈ tens of thousands of internet-exposed Zyxel firewall management interfaces (order of magnitude 10k–100k devices) | |
| CVE-2022-31499 | Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. Nortek Linear eMerge E3-Series devices before 0.32-08f allow an unauthenticated attacker to inject OS commands via ReaderNo. NOTE: this issue exists because of an incomplete fix for CVE-2019-7256. NVD description · AI analysis pending | 9.8 | 65% | PoC ×2 |
| — | |
| CVE-2022-37061 | All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject and execute arbitrary shell commands as the root user through the id HTTP POST parameter in the res.php endpoint. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the root privileges. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023) the FLIR AX8 should no longer be affected by the vulnerability reported. Latest firmware version (as of Oct 2025, was released Jun 2024) is 1.55.16. NVD description · AI analysis pending | 9.8 | 100% | PoC ×5 |
| — | |
| CVE-2022-40005 | Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTra Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the /boaform/formPing6 and /boaform/formTracert URIs for ping and traceroute. NVD description · AI analysis pending | 8.8 | 35% | PoC ×2 |
| — | |
| CVE-2022-45699 | Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter. NVD description · AI analysis pending | 9.8 | 77% | PoC ×2 |
| — | |
| CVE-2023-1389 | Command Injection in TP-Link Archer AX21 Router Allows Remote Code Execution CVE-2023-1389 is a command injection flaw (CWE-77) in TP-Link's Archer AX21 Wi-Fi 6 router that lets an attacker execute arbitrary operating-system commands on the device. It is triggered by sending crafted input to a remotely reachable service on the router, which passes attacker-controlled values to the device's shell without proper sanitization; the source data does not specify the vulnerable endpoint or exact affected firmware ranges. Successful exploitation yields remote code execution on the router, giving the attacker a foothold in the network where the router sits, from which they can pivot or abuse the device further. Any household or organization running an Archer AX21 router is affected, with the highest risk where the router's management interface is exposed to the internet. The flaw was added to CISA's KEV catalog on 2023-05-01, confirming exploitation in the wild; EPSS assigns a ~100% probability of exploitation within 30 days (top percentile), while no public proof-of-concept or ransomware association is documented in the source data. Do: Update the Archer AX21 to the latest firmware available from TP-Link per the vendor's instructions (fixed firmware is published on the product's TP-Link support page). If updating is not immediately possible, disable WAN-side/remote management and restrict the router's web interface to the local network. Because exploitation is confirmed in the wild, also review exposed routers for signs of compromise, such as unexplained configuration changes or unexpected outbound traffic. | 8.8 | 100% | KEV PoC ×2 |
| masslikely hundreds of thousands of routers deployed, with >100k plausibly internet-exposed | |
| CVE-2023-25280 | Unauthenticated OS Command Injection in D-Link DIR-820 Router (CVE-2023-25280) CVE-2023-25280 is an unauthenticated OS command injection flaw (CWE-78) in D-Link DIR-820 router firmware DIR820LA1_FW105B03, located in the ping.ccp web interface. A remote attacker with no credentials can send a crafted ping_addr parameter to ping.ccp, causing arbitrary operating-system commands to execute on the router. Successful exploitation escalates privileges to root, giving an attacker full control of the device for use as a botnet node or a foothold into the connected network. Users running the affected D-Link DIR-820 hardware are exposed, and because the product is end-of-life/end-of-service, fixes are not expected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-30, EPSS puts the 30-day exploitation probability at 97.9% (100th percentile), a public proof-of-concept is available, and active botnet campaigns such as RondoDox and Mirai-style campaigns are targeting flaws in this class of IoT devices. Do: Per CISA's KEV required action, discontinue use of this end-of-life/end-of-service product — retire or replace the DIR-820, since no patched firmware is expected. If replacement must be delayed, restrict the router's web interface so it is not reachable from the WAN, disable remote management, and monitor for signs of botnet infection such as unusual outbound traffic. When inventorying, verify installed firmware version (affected build: DIR820LA1_FW105B03). | 9.8 | 98% | KEV PoC |
| moderatelikely tens of thousands of internet-exposed units (estimated; no authoritative public scan count for this single end-of-life model) | |
| CVE-2023-27240 | Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip. Tenda AX3 V16.03.12.11 was discovered to contain a command injection vulnerability via the lanip parameter at /goform/AdvSetLanip. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| url | http://185.225.74[ | he proper bot clients for the specific Linux architectures: hxxp://185.225.74[.]251/armv4l hxxp://185.225.74[.]251/armv5l hxxp://185.225.7 |
Full article643 words · extracted from securityaffairs.com · click to collapse

Since March 2023, Unit 42 researchers have observed a variant of the Mirai botnet spreading by targeting tens of flaws in D-Link, Zyxel, and Netgear devices.
Since March 2023, researchers at Palo Alto Networks Unit 42 have observed a new variant of the Mirai botnet targeting multiple vulnerabilities in popular IoT devices. Below is the list of the targeted vulnerabilities:
| CVE/Product | Description |
| CVE-2019-12725 | Zeroshell Remote Command Execution Vulnerability |
| CVE-2019-17621 | D-Link DIR-859 Remote Command Injection Vulnerability |
| CVE-2019-20500 | D-Link DWL-2600AP Remote Command Execution Vulnerability |
| CVE-2021-25296 | Nagios XI Remote Command Injection Vulnerability |
| CVE-2021-46422 | Telesquare SDT-CW3B1 Router Command Injection Vulnerability |
| CVE-2022-27002 | Arris TR3300 Remote Command Injection Vulnerability |
| CVE-2022-29303 | SolarView Compact Command Injection Vulnerability |
| CVE-2022-30023 | Tenda HG9 Router Command Injection Vulnerability |
| CVE-2022-30525 | Zyxel Command Injection Vulnerability |
| CVE-2022-31499 | Nortek Linear eMerge Command Injection Vulnerability |
| CVE-2022-37061 | FLIR AX8 Unauthenticated OS Command Injection Vulnerability |
| CVE-2022-40005 | Intelbras WiFiber 120 AC inMesh Command Injection Vulnerability |
| CVE-2022-45699 | APsystems ECU-R Remote Command Execution Vulnerability |
| CVE-2023-1389 | TP-Link Archer Router Command Injection Vulnerability |
| CVE-2023-25280 | D-link DIR820LA1_FW105B03 Command injection vulnerability |
| CVE-2023-27240 | Tenda AX3 Command Injection Vulnerability |
| CCTV/DVR | CCTV/DVR Remote Code Execution |
| EnGenius EnShare | EnGenius EnShare Remote Code Execution Vulnerability |
| MVPower DVR | MVPower DVR Shell Unauthenticated Command Execution Vulnerability |
| Netgear DGN1000 | Netgear DGN1000 Remote Code Execution Vulnerability |
| Vacron NVR | Vacron NVR Remote Code Execution Vulnerability |
| MediaTek WiMAX | MediaTek WiMAX Remote Code Execution |
The botnet aims at taking control of D-Link, Arris, Zyxel, TP-Link, Tenda, Netgear, and MediaTek devices and uses them to carry out distributed denial-of-service (DDoS) attacks. The list of targeted devices includes routers, DVRs, access control systems, and Solar power generation monitoring systems.
The researchers observed two campaigns, respectively in March and June.
Since the beginning of the attacks observed in October 2022, threat actors have enhanced the botnet by integrating exploits for new vulnerabilities.
The attack chain commences with the exploitation of one of the above issues, then the threat actor tries to download a shell script downloader from a remote server.
Upon executing the script, it would download and execute the proper bot clients for the specific Linux architectures:
- hxxp://185.225.74[.]251/armv4l
- hxxp://185.225.74[.]251/armv5l
- hxxp://185.225.74[.]251/armv6l
- hxxp://185.225.74[.]251/armv7l
- hxxp://185.225.74[.]251/mips
- hxxp://185.225.74[.]251/mipsel
- hxxp://185.225.74[.]251/sh4
- hxxp://185.225.74[.]251/x86_64
- hxxp://185.225.74[.]251/i686
- hxxp://185.225.74[.]251/i586
- hxxp://185.225.74[.]251/arc
- hxxp://185.225.74[.]251/m68k
- hxxp://185.225.74[.]251/sparc
Once executed the bot client, the shell script downloader will delete the client executable file to avoid detection.
“Based on behavior and patterns Unit 42 researchers observed while analyzing the downloaded botnet client samples, we believe the sample is a variant of the Mirai botnet.” reads the report published by Unit42. “Upon execution, the botnet client prints listening tun0 to the console. The malware also contains a function that ensures only one instance of this malware runs on the same device. If a botnet process already exists, the botnet client will terminate the current running process and start a new one.”
The researchers pointed out that the Mirai variant like IZ1H9 and V3G4 will first initialize an encrypted string table and then retrieve the strings through an index. However, this Mirai variant will directly access the encrypted strings in the .rodata section via an index
The approach allows the malware to remain under the radar and be faster.
This Mirai variant lack of brute forcing login credentials capability, which means that operators have to manually deploy it by exploiting the above vulnerabilities.
“The widespread adoption of IoT devices has become a ubiquitous trend. However, the persistent security concerns surrounding these devices cannot be ignored. The Mirai botnet, discovered back in 2016, is still active today. A significant part of the reason for its popularity among threat actors lies in the security flaws of IoT devices.” concludes the report. “These remote code execution vulnerabilities targeting IoT devices exhibit a combination of low complexity and high impact, making them an irresistible target for threat actors. As a result, protecting IoT devices against such threats becomes an urgent task.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Mirai botnet)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/147750/malware/mirai-botnet-iot-devices.html