[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLTn0v8yX2uIx4P_-m0et01oZ8TDo8WGTgDocDVoUVI8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"3336b29a-7f4e-43fa-a339-b23f1347ce36","discontinued-d-link-routers-exploited-by-mirai-botnet-via-year-old-vulnerability","7a5e1df9-2720-4c0d-838a-295ebf4ebe44","Discontinued D-Link Routers Exploited by Mirai Botnet via Year-Old Vulnerability","Attackers are actively exploiting CVE-2025-29635, a command injection vulnerability in discontinued D-Link DIR-823X routers, to deploy Mirai botnet payloads. The vulnerability was publicly disclosed over a year ago with proof-of-concept code available on GitHub, yet remains unpatched because the affected router models no longer receive security updates from the vendor. This highlights the critical risk of operating end-of-life network equipment that cannot be secured against known vulnerabilities. Organizations must proactively identify and replace discontinued hardware before they become permanent security liabilities.","**Immediate actions:**\n- Identify and inventory all end-of-life network devices in your environment\n- Replace discontinued D-Link DIR-823X routers with supported models immediately\n- Block internet access to vulnerable devices that cannot be immediately replaced\n\n**Long-term improvements:**\n- Establish a hardware lifecycle management program with planned refresh cycles\n- Maintain vendor support contracts and monitor end-of-support announcements\n- Implement network segmentation to isolate legacy devices from critical systems\n\n**Detection measures:**\n- Deploy network monitoring to detect unusual POST requests and command injection attempts\n- Enable logging on all network appliances to identify potential compromise indicators\n- Scan for IoT devices and routers communicating with suspicious external IP addresses",[12,13,14,15,16,17],"CIS Control 1","CIS Control 7","CIS Control 12","NIST CM-8","NIST SI-2","NIST AC-4","published","2026-04-23T09:09:30.006354+00:00","2026-04-23T09:09:29.865+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Fmirai-botnet-targets-flaw-in-discontinued-d-link-routers\u002F","mirai-botnet-targets-flaw-in-discontinued-d-link-routers-deab0c","Mirai Botnet Targets Flaw in Discontinued D-Link Routers",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]