Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet
To launch distributed denial-of-service (DDoS) assaults, threat actors have been seen actively taking advantage of security holes in GeoVision end-of-life (EoL) Internet of Things (IoT) devices to ensnare them in a Mirai botnet.
The Akamai Security Intelligence and Response Team (SIRT) first noticed the activity in early April 2025. It entails taking advantage of two operating system command injection vulnerabilities (CVE-2024-6047 and CVE-2024-11120, CVSS scores: 9.8) that allow arbitrary system commands to be executed.
Kyle Lefton, a researcher at Akamai, told The Hacker News that the attack injects commands into the szSrvIpAddr parameter and targets the /DateSetting.cgi endpoint of GeoVision IoT devices.
The botnet was discovered injecting commands to download files as part of...

