By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet
Tech News

Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet

By Viral Trending Content 3 Min Read
Share
SHARE

May 06, 2025Ravie LakshmananInternet of Thing / Vulnerability

Threat actors have been observed actively exploiting security flaws in GeoVision end-of-life (EoL) Internet of Things (IoT) devices to corral them into a Mirai botnet for conducting distributed denial-of-service (DDoS) attacks.

The activity, first observed by the Akamai Security Intelligence and Response Team (SIRT) in early April 2025, involves the exploitation of two operating system command injection flaws (CVE-2024-6047 and CVE-2024-11120, CVSS scores: 9.8) that could be used to execute arbitrary system commands.

“The exploit targets the /DateSetting.cgi endpoint in GeoVision IoT devices, and injects commands into the szSrvIpAddr parameter,” Akamai researcher Kyle Lefton said in a report shared with The Hacker News.

Cybersecurity

In the attacks detected by the web security and infrastructure company, the botnet has been found injecting commands to download and execute an ARM version of the Mirai malware called LZRD.

Some of the vulnerabilities exploited by the botnet include a Hadoop YARN vulnerability, CVE-2018-10561, and a bug impacting DigiEver that was highlighted in December 2024.

There is some evidence to suggest that the campaign overlaps with previously recorded activity under the name InfectedSlurs.

“One of the most effective ways for cybercriminals to start assembling a botnet is to target poorly secured and outdated firmware on older devices,” Lefton said.

“There are many hardware manufacturers who do not issue patches for retired devices (in some cases, the manufacturer itself may be defunct).”

Given that the affected GeoVision devices are unlikely to receive new patches, it’s recommended that users upgrade to a newer model to safeguard against potential threats.

Samsung MagicINFO Flaw Exploited in Mirai Attacks

The disclosure comes as Arctic Wolf and the SANS Technology Institute warned of active exploitation of CVE-2024-7399 (CVSS score: 8.8), a path traversal flaw in Samsung MagicINFO 9 Server that could enable an attacker to write arbitrary files as system authority, to deliver the Mirai botnet.

Cybersecurity

While the issue was addressed by Samsung in August 2024, it has since been weaponized by attackers following the release of a proof-of-concept (PoC) on April 30, 2025, to retrieve and execute a shell script responsible for downloading the botnet.

“The vulnerability allows for arbitrary file writing by unauthenticated users, and may ultimately lead to remote code execution when the vulnerability is used to write specially crafted JavaServer Pages (JSP) files,” Arctic Wolf said.

Users are recommended to update their instances to version 21.1050 and later to mitigate potential operational impact.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Aiper IrriSense 2 Smart Irrigation System Review: Clever Yet Uneven

France buys supercomputer maker Bull in tech sovereignty push

A professor’s journey from humble beginnings to a higher doctorate of science

Samsung Galaxy Z Fold 8 Price Leak: Is a Huge Hike Coming?

Manna, Neurent, Sisterly among EY Entrepreneur of the Year finalists

TAGGED: botnet, Cyber Security, Cybersecurity, device security, GeoVision, Internet, Internet of Things, Malware, Remote Code Execution, Samsung, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Oura Ring 4 vs Samsung Galaxy Ring: Which is the Best Smart Ring?
Next Article Oops! Google leaks Android’s bold new makeover — here’s what’s changing
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Aiper IrriSense 2 Smart Irrigation System Review: Clever Yet Uneven
Tech News
Wilder beats Chisora as Londoner heads for retirement
Sports
Ryanair CEO says book summer trips before fares soar, predicting French air traffic controllers more likely to cause flight chaos than fuel shortages
Business
ZachXBT accuses Circle of $420M in 'compliance failures' since 2022
Crypto
GTA 5 continues a frustrating cycle with latest Xbox Game Pass exit
Gaming News
France buys supercomputer maker Bull in tech sovereignty push
Tech News
With the FTSE 100 down 5%+ investors should remember this legendary quote from Warren Buffett
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?