CVE-2025-29635Active Exploitation(dlink / dir-823x)

CRITICALCVSS 7.2 · HIGHCISA KEV

Exploitation observed; activity peaked at 20 mentions and remains active

Immediate actions

  • Patch dlink dir-823x systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function, triggering remote command execution.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-05-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-823x
  • dir-823x_firmware

Threat summary

  • Active exploitation appears in 54 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 68 mentions across 17 observed days

What's happening

  • Active exploitation reported across 54 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 39 signals
  • Disclosure: 6 classified signals
  • Peaked 15d ago at 20 mentions (2026-04-22); latest day: 1
  • 68 total mentions across 17 days

Affected systems

Vendors
Products
dir-823xdir-823x_firmware

3 versions affected across 2 products

Deep dive

Activity timeline68 mentions / 17d
05101520Mentions · 2026-04-21: 2Mentions · 2026-04-22: 20Mentions · 2026-04-23: 16Mentions · 2026-04-24: 7Mentions · 2026-04-25: 3Mentions · 2026-04-26: 4Mentions · 2026-04-27: 3Mentions · 2026-04-28: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 3Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 2Mentions · 2026-05-08: 1Mentions · 2026-06-21: 1Mentions · 2026-06-28: 1Mentions · 2026-08-20: 1PoC Mentioned / Linked · 2026-04-22: 3PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-06-28: 1PoC Mentioned / Linked · 2026-08-20: 1Exploit Tool / Code · 2026-04-23: 1Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-04-22: 20Active Exploitation · 2026-04-23: 16Active Exploitation · 2026-04-24: 4Active Exploitation · 2026-04-25: 1Active Exploitation · 2026-04-26: 3Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-01: 2Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-04-22: 3Patch / Workaround · 2026-04-23: 5Patch / Workaround · 2026-04-24: 2Patch / Workaround · 2026-04-26: 2Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 2Patch / Workaround · 2026-05-08: 1Technical Details · 2026-04-22: 10Technical Details · 2026-04-23: 9Technical Details · 2026-04-24: 6Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 2Technical Details · 2026-04-27: 2Technical Details · 2026-05-01: 2Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-08: 1Technical Details · 2026-06-28: 1Technical Details · 2026-08-20: 104-2104-2204-2304-2404-2504-2604-2704-2804-3005-0105-0405-0505-0605-0806-2106-2808-20
Signal classification4 categories
Active Exploitation
5479.4%
Disclosure
68.8%
Patch
57.4%
General
34.4%
Referenced assets44 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-212
Active Exploitation2
2026-04-2220
Active Exploitation20
2026-04-2316
Active Exploitation16
2026-04-247
Active Exploitation4Disclosure3
2026-04-253
Active Exploitation1Disclosure1General1
2026-04-264
Active Exploitation3General1
2026-04-273
Active Exploitation2Disclosure1
2026-04-281
Active Exploitation1
2026-04-301
Active Exploitation1
2026-05-013
Active Exploitation2General1
2026-05-041
Patch1
2026-05-051
Patch1
2026-05-062
Patch2
2026-05-081
Patch1
2026-06-211
Active Exploitation1
2026-06-281
Disclosure1
2026-08-201
Active Exploitation1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ Four vulnerabilities have been added to the CISA KEV Catalog CVE-2025-29635 - D-Link DIR-823X Command Injection Vulnerability CVE-2024-7399 - Samsung MagicINFO 9 Server Path Traversal Vulnerability CVE-2024-57728 - SimpleHelp Path Traversal Vulnerability CVE-2024-57726 - SimpleHelp Missing Authorization Vulnerability https://darkwebinformer.com/cisa-kev-catalog/

    Post summary

    Four CVEs have been added to the CISA KEV catalog, indicating they are known to be exploited, though the post lacks PoC, exploit code, or patch information.

    1602175.6K
    222.6K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Nueva campaña maliciosa de Mirai ataca routers D-Link de la serie DIR-823X Una nueva campaña maliciosa de Mirai está explotando la vulnerabilidad CVE-2025-29635 en routers D-Link de la serie DIR-823X https://blog.elhacker.net/2026/04/nueva-campana-maliciosa-de-mirai-ataca.html

    Post summary

    Mirai is actively exploiting CVE‑2025‑29635 on D‑Link DIR‑823X routers, as reported in the linked blog post.

    0611722.3K
    140.9K followersView on X
  • Aircorridor@_aircorridor
    Active Exploitation

    Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers https://securityaffairs.com/191135/malware/mirai-botnet-exploits-cve-2025-29635-to-target-legacy-d-link-routers.html

    Post summary

    The Mirai Botnet is actively exploiting CVE-2025-29635 against legacy D-Link routers, indicating real‑world attacks without mention of patches or technical details.

    060762.0K
    13.2K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Akamai SIRT warns of a new Mirai campaign weaponizing EOL D-Link routers via CVE-2025-29635. Protect your network from zombie botnets—retire old hardware now. #MiraiBotnet #DLink #CyberSecurity #IoT #CVE202529635 #InfoSec #Botnet #DDoS https://securityonline.info/mirai-botnet-dlink-command-injection-cve-2025-29635/ https://t.co/Aff4DMPTDs

    Post summary

    Akamai SIRT highlights that Mirai is actively weaponizing the CVE‑2025‑29635 flaw in end‑of‑life D‑Link routers, urging users to retire outdated hardware.

    130641.2K
    12.5K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Akamai's SIRT reports Mirai is actively exploiting CVE-2025-29635 to weaponize legacy D-Link DIR-823X routers via crafted POST requests, dropping a Mirai variant and fetching malware from external hosts. https://securityaffairs.com/191135/malware/mirai-botnet-exploits-cve-2025-29635-to-target-legacy-d-link-routers.html

    Post summary

    Mirai botnet is currently exploiting CVE‑2025‑29635 against legacy D‑Link DIR‑823X routers using crafted POST requests, indicating active exploitation in the wild.

    120701.1K
    22.4K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/24追加) 🛡️No.1581 CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / NVD ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Samsung MagicINFO 9 Server 21.1050未満において、制限されたディレクトリ外へのパス操作により、事前認証されていない攻撃者が任意のファイルをsystem authorityに書き込まれる恐れがある。Arctic Wolfの報告では、細工したJSPファイルのアップロードによりリモートコード実行に至る可能性がある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅攻撃前提条件 ・Samsung MagicINFO 9 Server 21.1050未満が稼働していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ・認証は不要。 ✅悪用時影響 ・任意のファイルを書き込まれる ・system authorityでファイルを書き込まれる ・細工したJSPファイルを配置された場合、リモートコードの実行 ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み。Arctic Wolfは、2025年5月初旬に本脆弱性の実環境での悪用を観測したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-7399 https://security.samsungtv.com/securityUpdates https://davidxbors.github.io/0xpages/posts/cve-2024-7399/ https://arcticwolf.com/resources/blog/cve-2024-7399/ 🛡️No.1582 CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability ✅概要 ・深刻度:緊急 9.9 (CVSS Base) / NVD ・種別:認証の欠如 (CWE-862) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H SimpleHelp remote support software において、低権限の technician が過剰な権限を持つ API key を作成でき、その API key を用いて server admin 権限昇格される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp の脆弱バージョンが稼働していること。 ・攻撃者が低権限の technician アカウントを有していること。 ・攻撃者が対象サーバへネットワーク越しに到達可能であること。 ✅悪用時影響 ・過剰な権限を持つ API key を作成される可能性がある。 ・server admin 権限へ昇格される可能性がある。 ・管理者化により、低権限 technician が本来アクセスできない接続先 client machine にアクセスされる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Microsoft は Storm-1175 が CVE-2024-57726 を含む SimpleHelp の脆弱性を悪用していたと報告し、Trend Micro も DragonForce が CVE-2024-57726 を悪用して低権限ユーザーから管理者アクセスを得ていたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57726 https://guides.simple-help.com/kb---security-vulnerabilities-01-2025 https://horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/ 🛡️No.1583 CVE-2024-57728 SimpleHelp Path Traversal Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / NVD (NVD) ・種別:リンク解釈の問題 (CWE-59) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) SimpleHelp remote support software v5.5.7以前において、管理者ユーザーが細工されたZIPファイルをアップロードすることで、ファイルシステム上の任意の場所へファイルを書き込まれる恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・SimpleHelp v5.5.7以前の脆弱バージョンが稼働していること。 ・攻撃者が管理者ユーザー、または管理者権限を持つtechnicianとしてログイン可能であること。 ・細工されたZIPファイルをアップロードできること。 ✅悪用時影響 ・ファイルシステム上の任意の場所にファイルを書き込まれる可能性がある。 ・SimpleHelpサーバーユーザー権限で任意コード実行に至る可能性がある。 ・Linuxサーバではcrontabファイルの配置、WindowsサーバではSimpleHelpが使用する実行ファイルやライブラリの上書きにより悪用される可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Trend Microは、DragonForceがSimpleHelpの脆弱性としてCVE-2024-57728をラテラルムーブメントや情報収集に悪用していたと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2024-57728 https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-dragonforce 🛡️No.1584 CVE-2025-29635 D-Link DIR-823X Command Injection Vulnerability ✅概要 ・深刻度:重要 7.2 (CVSS Base) / CISA-ADP (NVD) ・種別:コマンドインジェクション (CWE-77) (NVD) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD) D-Link DIR-823X ファームウェア 240126 および 240802 には、/goform/set_prohibiting への POST リクエストを通じて任意のコマンドを実行される恐れがある。 対象機器の DIR-823X は、D-Link により EOL/EOS とされており、D-Link は停止と置き換えを推奨。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:高 ✅攻撃前提条件 ・D-Link DIR-823X のファームウェア 240126 または 240802 が稼働していること。 ・攻撃者が対象機器へネットワーク越しに到達可能であること。 ・認証済みの攻撃者であること。 ✅悪用時影響 ・リモートで任意のコマンドを実行される可能性がある。 ・機密性、完全性、可用性に高い影響が生じる可能性がある。 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。Akamai SIRT は、2026年3月初旬にグローバルなハニーポット網でこの脆弱性の悪用を確認し、Mirai 亜種の展開に使われていると報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-29635 https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10469 https://www.akamai.com/blog/security-research/cve-2025-29635-mirai-campaign-targets-d-link-devices https://www.cisa.gov/news-events/alerts/2026/04/24/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA catalogs multiple high‑severity CVEs with confirmed in‑the‑wild exploitation, available Proof of Concept code, and vendor mitigations, highlighting active threat exploitation.

    000415.0K
    43.6K followersView on X
  • のらねこ!中華パーツ自作PC本頒布中@ragemax
    Active Exploitation

    新たなMiraiの亜種、生産終了のD-Linkルーターを標的に(CVE-2025-29635) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45390/ >>このマルウェアには、「AI. NEEDS. TO. DIE(AIは死すべき)」という珍しいメッセージがハードコードされており 思想が強いな

    Post summary

    A new Mirai variant targeting retired D‑Link routers is linked to CVE‑2025‑29635, but the report offers no PoC, exploit code, patches, or detailed technical information.

    02030821
    5.9K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers https://securityaffairs.com/191135/malware/mirai-botnet-exploits-cve-2025-29635-to-target-legacy-d-link-routers.html

    Post summary

    The Mirai botnet is reportedly exploiting CVE‑2025‑29635 against legacy D‑Link routers, indicating active in‑the‑wild usage, but the post provides no further technical or remediation details.

    110301.4K
    158.1K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 Mirai botnet exploits D-Link routers (CVE-2025-29635) Command injection → malware drop + botnet recruitment 💡 Lesson: Old vulnerabilities + public PoC = easy targets for botnet operators ⚠️ Action: Replace unsupported devices, patch immediately, and block suspicious outbound traffic https://securityaffairs.com/191135/malware/mirai-botnet-exploits-cve-2025-29635-to-target-legacy-d-link-routers.html

    Post summary

    CVE‑2025‑29635 is being actively exploited by the Mirai botnet via command injection on D‑Link routers, underscoring the need for immediate patches and device replacement.

    10031549
    16.1K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    📋CISA added four actively exploited vulnerabilities to the KEV catalog: 🔸CVE-2024-57726 / CVE-2024-57728 — SimpleHelp (privilege escalation + path traversal, linked to DragonForce ransomware) 🔸CVE-2024-7399 — Samsung MagicINFO 9 Server path traversal (Mirai delivery observed) 🔸CVE-2025-29635 — D-Link DIR-823X command injection (EOL device, no patch retire it) Federal deadline: May 8, 2026. 📄 Source: CISA 👉 Follow @VulnerabilityNw — full catalog coverage on our Telegram → http://t.me/VulnerabilityNews

    Post summary

    CISA highlights four vulnerabilities that are actively being exploited—affecting SimpleHelp, Samsung MagicINFO, and a D-Link device—alongside recommendations for patch status and device retirement.

    11020161
    185 followersView on X
  • Anavem.com@Anavem_
    Active Exploitation

    Mirai Botnet Exploits D-Link Router Flaw CVE-2025-29635 #cve202529635 #dlinkrouter #miraibotnet https://www.anavem.com/en/news/cybersecurity/mirai-botnet-exploits-d-link-router-flaw-cve-2025-29635

    Post summary

    An article reports the Mirai botnet is actively exploiting CVE-2025-29635 on D-Link routers, though details on the vulnerability or mitigation remain sparse.

    01021447
    146 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-29635 - high 🚨 D-Link DIR-823X set_prohibiting - Command Injection > D-Link DIR-823X 240126 and 240802 contain a command injection caused by sending a POS... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-29635 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2025‑29635 is reported as a high‑severity command injection affecting D‑Link DIR‑823X routers, with a Nuclei template reference for detection.

    00012309
    958 followersView on X
  • Akamai Security Intelligence Group@akamai_research
    Active Exploitation

    The Akamai Security Intelligence and Response Team (SIRT) has identified active exploitation of command injection vulnerability CVE-2025-29635 against D-Link DIR-823X series routers. Full details: https://ow.ly/LJmE50YTvZw

    Post summary

    The Akamai SIRT reports that CVE‑2025‑29635, a command‑injection flaw in D‑Link DIR‑823X routers, is currently being actively exploited in the wild.

    01020719
    25.5K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Mirai botnet exploits CVE-2025-29635 command injection flaw in discontinued D-Link DIR-823X routers via crafted POST requests. Akamai observed active exploitation starting March 2026, one year after PoC disclosure. #DFIR_Radar https://t.co/6wTi7prC4p

    Post summary

    The tweet indicates Mirai botnet is actively exploiting a command injection flaw in discontinued D-Link DIR-823X routers since March 2026, one year after the PoC was disclosed.

    10020587
    1.7K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting D-Link routers (CVE-2025-29635) 2026-08-18 09:13:31 UTC Source IP: 77.239.124.109 🇳🇱 POST /goform/set_prohibiting IOCs: hxxp://31.77.227.102/dlink.sh 31.77.227.102 🇺🇸 6c49d14c0edfd2acfd8ea90305c302ef https://t.co/CaR8bJzznE

    Post summary

    The post reports a real‑time RCE attempt against D‑Link routers using CVE‑2025‑29635, complete with an attacker IP and a linked malicious script, indicating that the vulnerability is being actively exploited.

    01010294
    1.7K followersView on X
  • Toad Enjoyer@pondwatcher_med
    General

    🐸 CVE-2025-29635 on end-of-life D-Link. worth noting: MikroTik routers explicitly labeled "SCADA" appear internet-facing in Shodan scans across southern Europe. different vendor, same problem. OT gateways treated like home routers. patch windows are shorter than procurement cycles. always.

    Post summary

    The post notes the presence of CVE-2025-29635 on end‑of‑life D‑Link devices and that MikroTik routers labeled ‘SCADA’ are exposed online, but provides no technical details, exploit code, or patch information.

    00011798
    38 followersView on X
  • ThreatLevel@ThreatLevelAI
    Active Exploitation

    ⚠️ New vulnerability just added to the CISA KEV catalog Command Injection in D-Link DIR-823X (CVE-2025-29635) 📊 CVSS Score: 7.2 (High) 🔐 Authentication required ⚙️ Exploitable in default configuration 🔥 Active exploitation in the wild 🌐 Mixed internet/internal deployment 🎯 ThreatLevel Priority: Planned Fix Full analysis 👇 https://threatlevel.io/CVE-2025-29635?utm_source=x&utm_campaign=ob34lZFa

    Post summary

    A newly documented command injection vulnerability (CVE-2025-29635) in D-Link DIR‑823X has entered the CISA KEV catalog, is actively exploited in the wild, and includes details such as authentication requirements and default configuration exploitability.

    00011615
    6 followersView on X
  • Cyber News Live@cybernewslive
    Active Exploitation

    A hacking gang is actively hijacking D-Link DIR-823X routers using a known security flaw — vulnerability (CVE-2025-29635) — to conscript them into a botnet that launches large-scale attacks on websites and services. D-Link stopped supporting this router model in November 2024 and will not release a fix. Your router may already be compromised and participating in attacks without any visible sign. If you own a D-Link DIR-823X, replace it with a currently supported model — no patch is coming. ☠️ #CyberNewsLive https://bleepingcomputer.com/news/security/new-mirai-campaign-exploits-rce-flaw-in-eol-d-link-routers/

    Post summary

    The post reports that a hacking gang is actively exploiting CVE-2025-29635 to hijack D-Link DIR‑823X routers, creating a botnet; no patch will be released, so users should replace the device.

    01001569
    1.8K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    🚨 Acaba de confirmarse: Mirai Botnet está explotando la vulnerabilidad CVE-2025-29635 en routers D-Link legacy para targeting dispositivos vulnerables. El botnet Mirai está atacando a routers D-Link de generaciones anteriores, aprovechando una vulnerabilidad de inyección de comandos que permite a los atacantes inyectar comandos maliciosos. La vulnerabilidad, identificada como CVE-2025-29635, se puede explotar a través de solicitudes POST maliciosas. La campaña de ataque parece estar dirigida a dispositivos legacy que no han recibido actualizaciones de seguridad recientes, lo que los hace vulnerables a este tipo de ataques. Aunque no tengo acceso a detalles específicos sobre el número de dispositivos afectados, es importante que los dueños de routers D-Link legacy tomen medidas para protegerse. Si usas un router D-Link legacy, es crucial que revises si tu dispositivo está afectado y tomes medidas para actualizar o reemplazarlo lo antes posible. ¿Estás en riesgo? Revisa esto: actualiza tu router o considera reemplazarlo por uno más seguro. #CiberseguridadMX #RoutersVulnerables #CVE202529635 https://securityaffairs.com/191135/malware/mirai-botnet-exploits-cve-2025-29635-to-target-legacy-d-link-routers.html

    Post summary

    The post reports that the Mirai botnet is actively exploiting CVE‑2025‑29635, a command‑injection flaw in legacy D‑Link routers via malicious POST requests, and urges owners to update or replace affected devices.

    00020334
    153 followersView on X
  • hackplayers@hackplayers
    Active Exploitation

    Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers https://securityaffairs.com/191135/malware/mirai-botnet-exploits-cve-2025-29635-to-target-legacy-d-link-routers.html

    Post summary

    The article reports that the Mirai botnet is actively exploiting CVE-2025-29635 against legacy D‑Link routers, but it offers neither exploit code nor detailed vulnerability information.

    00011721
    54.9K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-823x---
OSdlinkdir-823x_firmware240126--
OSdlinkdir-823x_firmware240802--

Explore more