Discontinued D-Link Routers Become Mirai Entry Point

A retired router can still become a botnet foothold if it stays online. Here, the problem is not just the command injection in D-Link DIR-823X firmware. It is that a year-old proof of concept gave Mirai operators a ready-made path to turn exposed devices into payload loaders. Akamai says CVE-2025-29635 affects DIR-823X firmware 240126 and 24082. The flaw is triggered with crafted POST requests, and the observed activity follows the same code path and system call used by the removed GitHub PoC from last year. The payload shows Mirai traits, including XOR encoding, a hardcoded console execution string, and a hardcoded downloader IP. The risk persists because the affected devices are discontinued and no longer receive vendor updates. That leaves retirement or isolation as the only meaningful control, and it lowers the skill bar for future abuse of the same class of exposed IoT gear.

Part of the PlainSec briefing for 2026-04-23

Sources