- A vulnerability in an old camera is used to create a botnet
- The camera is no longer supported by its supplier and does not receive a patch
- Users are advised to move to a newer model
Security researchers warn that cyber criminals abuse a vulnerability of command injection in an old IP camera to build a botnet.
The IC-7100, made by a Taiwanese network gear manufacturer called Edimax, is vulnerable to a command injection error caused by incorrect neutralization of incoming requests, found security researchers from Akamai.
Akamai says a malicious group is using this mistake right now to build a botnet -but it is not known which botnet or how big it is -although botnets are usually used in DDOS attacks, illegal proxy services, ad click -click -frs and more.
Obtain confidential information
The error is traced as CVE-2025-1316 and has a severity of 9.3/10 (critical). It allows threat actors to send a specially developed request to the device and thus get remote code execution functions (RCE).
The US Cyber Security and Infrastructure Security Agency (CISA) allegedly tried to reach Edimax without help. Akamai was something luckier, and was told by Edimax that the camera reached the end of life and was no longer supported. However, the manufacturer did not say if other newer models were also susceptible to the same mistake and whether it would soon address it.
The Edimax IC-7100 is a network camera designed to monitor the home and small businesses. It is used by homeowners, small businesses and retail stores, in offices and by remote workers. It was released in 2011 and its discontinuation date is not specified. Unfortunately, many owners do not keep track of outdated gears and continue to use hardware and software that is no longer supported, which puts themselves at risk.
Unfortunately, the only way to defend against this attack on removing the cameras and replacing them with newer, supported models. Putting it behind Firewall can help mitigate the risk, but it will not eliminate it completely.
Via Bleeping computer