Back to all lessons
Awareness Lessons
6 months ago

Discontinued D-Link Routers Exploited by Mirai Botnet via Year-Old Vulnerability

Attackers are actively exploiting CVE-2025-29635, a command injection vulnerability in discontinued D-Link DIR-823X routers, to deploy Mirai botnet payloads. The vulnerability was publicly disclosed over a year ago with proof-of-concept code available on GitHub, yet remains unpatched because the affected router models no longer receive security updates from the vendor. This highlights the critical risk of operating end-of-life network equipment that cannot be secured against known vulnerabilities. Organizations must proactively identify and replace discontinued hardware before they become permanent security liabilities.

Tactical Insight

Immediate actions

  • Identify and inventory all end-of-life network devices in your environment
  • Replace discontinued D-Link DIR-823X routers with supported models immediately
  • Block internet access to vulnerable devices that cannot be immediately replaced

Long-term improvements

  • Establish a hardware lifecycle management program with planned refresh cycles
  • Maintain vendor support contracts and monitor end-of-support announcements
  • Implement network segmentation to isolate legacy devices from critical systems

Detection measures

  • Deploy network monitoring to detect unusual POST requests and command injection attempts
  • Enable logging on all network appliances to identify potential compromise indicators
  • Scan for IoT devices and routers communicating with suspicious external IP addresses