Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»New Mirai campaign exploits RCE flaw in EoL D-Link routers
    Cybersecurity

    New Mirai campaign exploits RCE flaw in EoL D-Link routers

    adminBy adminApril 22, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    D-Link
    Share
    Facebook Twitter LinkedIn Pinterest Email

    D-Link

    A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet.

    CVE-2025-29635 allows an attacker to execute arbitrary commands on remote devices by sending a POST request to a vulnerable endpoint, triggering remote command execution (RCE).

    Akamai’s SIRT, which detected the Mirai campaign in March 2026, reports that, although the flaw was first disclosed 13 months ago by security researchers Wang Jinshuai and Zhao Jiangting, this is the first time in-the-wild active exploitation has been observed.

    image

    “The Akamai SIRT discovered active exploitation attempts of the D-Link command injection vulnerability CVE-2025-29635 in our global network of honeypots in early March 2026,” reads Akamai’s report.

    “This vulnerability exists in D-Link DIR-823X series routers in firmware versions 240126 and 24082, and allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to the /goform/set_prohibiting endpoint via the corresponding function, which can trigger remote command execution.”

    The researchers who discovered the flaw briefly published a proof-of-concept (PoC) exploit on GitHub, but later retracted it.

    Akamai’s observations show attackers are sending POST requests that change directories across writable paths, download a shell script (dlink.sh) from an external IP, and execute it.

    The observed POST requests
    The observed POST requests
    Source: Akamai

    The script installs a Mirai-based malware named “tuxnokill,” which supports multiple architectures.

    In terms of capabilities, it features Mirai’s standard distributed denial-of-service (DDoS) attack repertoire, including TCP SYN/ACK/STOMP, UDP floods, and HTTP null.

    Akamai has also found that the threat actor behind this campaign also exploits CVE-2023-1389, impacting TP-Link routers, and a separate RCE flaw in ZTE ZXV10 H108L routers. The same attack pattern was observed across all of them, leading to the deployment of a Mirai payload.

    The impacted devices reached end of life (EoL) in November 2024, so it’s likely the latest firmware available for the model does not address CVE-2025-29635. D-Link does not make exceptions when active exploitation is detected, so it’s unlikely the vendor will provide a fixing patch now.

    BleepingComputer has contacted D-Link with questions about the reported activity and the status of the fix, and we will update this post as soon as we hear back.

    Meanwhile, users of routers that have reached EoL are recommended to upgrade to a newer model that enjoys active support with frequent security fixes, disable remote administration portals if not needed, change default admin passwords, and monitor for unexpected configuration changes.


    article image

    AI chained four zero-days into one exploit that bypassed both renderer and OS sandboxes. A wave of new exploits is coming.

    At the Autonomous Validation Summit (May 12 & 14), see how autonomous, context-rich validation finds what’s exploitable, proves controls hold, and closes the remediation loop.

    Claim Your Spot

    Campaign DLink EoL Exploits Flaw Mirai RCE Routers
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleAEO metrics every marketer should track in 2026
    Next Article 9 Netflix shows canceled or ending in 2026, so far
    admin
    • Website

    Related Posts

    Trump’s CISA director pick withdraws after tumultuous nomination

    April 22, 2026

    After Bluesky, Mastodon Targeted in DDoS Attack

    April 22, 2026

    DPRK Fake Job Scams Self-Propagate in ‘Contagious Interview’

    April 22, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    10 Hacks Every Brave Browser User Should Know

    April 22, 2026

    How AI is changing copper, fiber networking

    April 22, 2026

    Trump’s CISA director pick withdraws after tumultuous nomination

    April 22, 2026

    Google Ads Posts GEO Partner Manager Role

    April 22, 2026
    Categories
    • Blogging (67)
    • Cybersecurity (1,451)
    • Privacy & Online Earning (179)
    • SEO & Digital Marketing (886)
    • Tech Tools & Mobile / Apps (1,739)
    • WiFi / Internet & Networking (241)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    10 Hacks Every Brave Browser User Should Know

    April 22, 2026

    How AI is changing copper, fiber networking

    April 22, 2026

    Trump’s CISA director pick withdraws after tumultuous nomination

    April 22, 2026
    Most Popular
    • 10 Hacks Every Brave Browser User Should Know
    • How AI is changing copper, fiber networking
    • Trump’s CISA director pick withdraws after tumultuous nomination
    • Google Ads Posts GEO Partner Manager Role
    • 9 Netflix shows canceled or ending in 2026, so far
    • New Mirai campaign exploits RCE flaw in EoL D-Link routers
    • AEO metrics every marketer should track in 2026
    • I stopped dreading the terminal after finding these 4 tools
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.