logo

Command Injection Vulnerability (CVE-2025-29635) Exploited in the Wild

ID: 0116b1df-6517-5053-872c-e45bc5296bca

STIX ID: report--0116b1df-6517-5053-872c-e45bc5296bca

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Akamai SIRT reports active exploitation of CVE-2025-29635 against end-of-life D-Link DIR-823X routers, where a POST to the /goform/set_prohibiting endpoint enables remote command execution and infection by a Mirai variant; the activity was observed in honeypots and organizations are urged to retire EOL devices, apply patches or network protections, and monitor disclosures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.