CVE-2025-29635
Known exploited · CISA KEV
CVSS 8.8 HIGH: a command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute… EPSS 88% (100th percentile).
CISA federal remediation date May 8
Vulnerabilities & Exploits · Web App Attack
A retired router can still become a botnet foothold if it stays online. Here, the problem is not just the command injection in D-Link DIR-823X firmware. It is that a year-old proof of concept gave Mirai operators a ready-made path to turn exposed devices into payload loaders.
Akamai says CVE-2025-29635 affects DIR-823X firmware 240126 and 24082. The flaw is triggered with crafted POST requests, and the observed activity follows the same code path and system call used by the removed GitHub PoC from last year. The payload shows Mirai traits, including XOR encoding, a hardcoded console execution string, and a hardcoded downloader IP.
The risk persists because the affected devices are discontinued and no longer receive vendor updates. That leaves retirement or isolation as the only meaningful control, and it lowers the skill bar for future abuse of the same class of exposed IoT gear.
1 source · Apr 22
Known exploited · CISA KEV
CVSS 8.8 HIGH: a command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute… EPSS 88% (100th percentile).
CISA federal remediation date May 8
SecurityWeek
Mirai Botnet Targets Flaw in Discontinued D-Link Routers
The exploitation of the command injection vulnerability started one year after public disclosure and PoC exploit code publication.
originalPart of the PlainSec briefing for 2026-04-23
Every edition of this story: Discontinued D-Link Routers Become Mirai Entry Point