Unpatched Edimax Camera Flaw Exploited for Mirai Botnet Attacks Since Last Year

Since at least May 2024, threat actors have been using an unpatched security hole in the Edimax IC-7100 network camera to distribute variations of the Mirat botnet malware.

With a well constructed request, an attacker might use the critical operating system command injection vulnerability CVE-2025-1316 (CVSS v4 score: 9.3) to remotely execute code on vulnerable devices.

Although a proof-of-concept (PoC) exploit has been accessible to the public since June 2023, web infrastructure and security firm Akamai stated that the first exploit attempt aimed at the vulnerability dates back to May 2024.

The exploit inserts commands into the NTP_serverName option as part of the ipcamSource option of param.cgi, targeting the /camera-cgi/admin/param.cgi endpoint of Edimax devices read more about Unpatched Edimax Camera Flaw Exploited for Mirai Botnet Attacks Since Last Year.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *