


Perceptive Security
SOC/SIEM Consultancy

New Mirai campaign exploits RCE flaw in EoL D-Link routers
Published:
22 April 2026 at 20:04:46
Alert date:
22 April 2026 at 22:11:22
Source:
bleepingcomputer.com
Network Infrastructure, Ransomware & Malware, Mobile & IoT
A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command injection vulnerability in D-Link DIR-823X routers. The vulnerability affects end-of-life router models, allowing attackers to execute remote code execution attacks. Compromised devices are being enlisted into the Mirai botnet for malicious activities. The campaign targets unpatched routers that are no longer receiving security updates from D-Link. This represents an active threat to users of these legacy networking devices.
Technical details
Mitigation steps:
Affected products:
D-Link DIR-823X
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
