CVE-2024-45163Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-15); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-15: 2Mentions · 2026-03-31: 1Mentions · 2026-04-07: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-11: 1Technical Details · 2026-03-15: 2Technical Details · 2026-04-07: 103-1503-3104-0704-11
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-152
Disclosure2
2026-03-311
General1
2026-04-071
Disclosure1
2026-04-111
PoC1
Full discourse5 posts
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2024-45163: Remote DoS in Mirai C2 – research writeup + what it led me to build https://flowtriq.com/blog/cve-2024-45163

    Post summary

    The text references a research write‑up on CVE‑2024‑45163, a remote DoS vulnerability in Mirai C2, noting that it inspired the author to develop something further.

    140621.1K
    32.8K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2024-45163: Remote DoS in Mirai C2 – research writeup + what it led me to build https://flowtriq.com/blog/cve-2024-45163

    Post summary

    The post announces CVE-2024-45163, a Remote DoS flaw in Mirai’s C2, and points to a research writeup detailing the discovery.

    010441.9K
    153.1K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2024-45163: Remote DoS in Mirai C2 – research writeup + what it led me to build https://flowtriq.com/blog/cve-2024-45163

    Post summary

    A blog post announces a Remote DoS vulnerability (CVE-2024-45163) affecting Mirai C2, offering a research writeup and hinting at a constructed tool, but lacks detailed exploit or patch information.

    02020402
    33.3K followersView on X
  • Jacob Masse@thejacobmasse
    General

    We just launched Flowtriq on @ProductHunt 🎉 I found a kill switch in the Mirai botnet (CVE-2024-45163). That research taught me what DDoS attacks look like at the packet level. So I built Flowtriq: → Installs in 2 minutes (pip install ftagent) → Detects DDoS attacks in <1 second → Auto-deploys BGP FlowSpec, RTBH, and cloud scrubbing → Full PCAP forensics on every attack → $9.99/node/month. No bandwidth surcharges. Built for NOC teams, hosting providers, game server operators, and ISPs who are tired of sampled NetFlow telling them about an attack 3 minutes too late. 7-day free trial, no credit card. Plus there's an exclusive 50% off code on our Product Hunt page. https://www.producthunt.com/products/flowtriq https://flowtriq.com

    Post summary

    The post notes a discovery of a kill switch in Mirai botnet CVE-2024-45163 but provides no technical, exploit, or patch details, focusing instead on launching the Flowtriq product.

    1001062
    94 followersView on X
  • Jacob Masse@thejacobmasse
    PoC

    In 2024, I found a way to kill any Mirai botnet command server on the internet with a single packet. No authentication needed. CVE-2024-45163. I'd been inside live Mirai C2 infrastructure at that point. Running network ops, coordinating takedowns, watching botnets spin up in real time. When you spend that long staring at attack traffic, you start noticing things... (1/4)

    Post summary

    The author reports discovering a single‑packet method to terminate Mirai C2 servers, indicating a proof of concept, but offers no technical specifics or exploit code.

    1000092
    93 followersView on X

Explore more