Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Photos of Milan Fashion Week’s menswear for Spring-Summer 2026

June 23, 2025

What to Stream: Lorde, ‘The Bear’ and ‘A Minecraft Movie’

June 23, 2025

Simon Cracker creates brand uniform for Milan Fashion Week

June 22, 2025
Facebook X (Twitter) Instagram
Trending
  • Photos of Milan Fashion Week’s menswear for Spring-Summer 2026
  • What to Stream: Lorde, ‘The Bear’ and ‘A Minecraft Movie’
  • Simon Cracker creates brand uniform for Milan Fashion Week
  • Prada wants to change the conversation away from aggression, toward gentleness
  • 2,500 revelers in baroque costumes dance until dawn at Versailles’ masked ball
  • Armani’s global aesthetic shines in bohemian Emporio Armani show, though designer misses Milan bow
  • Greenland celebrates its National Day to mark the summer solstice
  • Stonehenge solstice sunrise draws druids, pagans and revelers
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Monday, June 23
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Edimax Says No Patches Coming for Zero-Day Exploited by Botnets
Cybersecurity

Edimax Says No Patches Coming for Zero-Day Exploited by Botnets

adminBy adminMarch 11, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 49


Taiwan-based networking solutions provider Edimax says it’s aware of reports that a vulnerability affecting some of its cameras has been exploited in the wild, but it cannot release patches due to the product being discontinued more than a decade ago.

The cybersecurity agency CISA warned organizations on March 4 about CVE-2025-1316, a critical command execution vulnerability affecting Edimax IC-7100 IP cameras.

The agency suggested that the vulnerability may have been exploited as a zero-day, but did not clearly state it in its advisory.

However, Akamai, whose researchers have been credited for reporting the flaw, confirmed to SecurityWeek that the vulnerability has been exploited as a zero-day by multiple Mirai-based botnets. CVE-2025-1316 is just one of the many flaws in these botnets’ arsenal. 

Edimax camera zero-day
Edimax camera zero-day

Akamai pointed out that exploitation of CVE-2025-1316 requires authentication, but threat actors have completed this requirement by relying on the fact that many internet-exposed devices are still protected by known default credentials.

Once they have gained access to a device, threat actors run a command execution exploit and execute a shell script that downloads a Mirai payload from a remote server.

SecurityWeek reached out to Edimax for comment before publishing an article on March 7, but the vendor has only now responded. The company notified us on Tuesday that it has issued a statement on the matter. 

Edimax says it takes product security and user data protection very seriously — despite claims from CISA and Akamai that the vendor has not been responsive to responsible disclosure attempts — but it’s unable to release a patch for CVE-2025-1316.

“The Edimax IC-7100 is a legacy product that was discontinued over 10 years ago, and its technical support and firmware maintenance were officially terminated,” Edimax explained. “Due to the unavailability of the development environment and source code, we regret to inform that no security patch or firmware update can be provided for this product.”

Advertisement. Scroll to continue reading.

Users still relying on the vulnerable cameras have been advised by the vendor to avoid exposing their devices directly to the internet and to use a firewall or NAT to restrict external access. In addition, users should change default credentials and monitor device access logs for unusual activity.

Despite being the first to suggest active exploitation of the vulnerability, CISA even now has yet to add CVE-2025-1316 to its Known Exploited Vulnerabilities (KEV) catalog. 

Related: Exploitation Long Known for Most of CISA’s Latest KEV Additions

Related: Exploited VMware ESXi Flaws Put Many at Risk of Ransomware, Other Attacks



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Billionaire Jorge Pérez Plans To Beat Trump’s Immigration Crackdown

June 18, 2025

Jorge Pérez made his fortune selling luxury condos in South Florida. Now the wealthy immigrant…

Indian Creek Property Near Jeff Bezos Just Sold For Over $100 Million

June 17, 2025

How Much Is Barron Trump Worth?

June 17, 2025

Trump Just Disclosed Earning $57.4 Million From World Liberty Financial—Here’s What We Know

June 16, 2025
Our Picks

Photos of Milan Fashion Week’s menswear for Spring-Summer 2026

June 23, 2025

What to Stream: Lorde, ‘The Bear’ and ‘A Minecraft Movie’

June 23, 2025

Simon Cracker creates brand uniform for Milan Fashion Week

June 22, 2025

Prada wants to change the conversation away from aggression, toward gentleness

June 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.