Awareness Lessons
6 months ago
Discontinued D-Link Routers Exploited by Mirai Botnet via Year-Old Vulnerability
Attackers are actively exploiting CVE-2025-29635, a command injection vulnerability in discontinued D-Link DIR-823X routers, to deploy Mirai botnet payloads. The vulnerability was publicly disclosed over a year ago with proof-of-concept code available on GitHub, yet remains unpatched because the affected router models no longer receive security updates from the vendor. This highlights the critical risk of operating end-of-life network equipment that cannot be secured against known vulnerabilities. Organizations must proactively identify and replace discontinued hardware before they become permanent security liabilities.
Tactical Insight
Immediate actions
- Identify and inventory all end-of-life network devices in your environment
- Replace discontinued D-Link DIR-823X routers with supported models immediately
- Block internet access to vulnerable devices that cannot be immediately replaced
Long-term improvements
- Establish a hardware lifecycle management program with planned refresh cycles
- Maintain vendor support contracts and monitor end-of-support announcements
- Implement network segmentation to isolate legacy devices from critical systems
Detection measures
- Deploy network monitoring to detect unusual POST requests and command injection attempts
- Enable logging on all network appliances to identify potential compromise indicators
- Scan for IoT devices and routers communicating with suspicious external IP addresses