Affected Systems
DD-WRT router firmware (specific versions not disclosed). Affects devices across multiple CPU architectures. No CVE assigned yet.
Exploitation Status
Active exploitation confirmed. Gafgyt C0XMO variant is actively propagating in the wild and compromising DD-WRT routers. The botnet includes functionality to terminate competing malware processes on infected systems.
Business Impact
Organizations using DD-WRT firmware on routers face immediate risk of botnet infection. Compromised routers can be used for DDoS attacks, lateral movement, or as pivot points into internal networks. The malware's ability to kill rival infections suggests a competitive botnet landscape targeting these devices. Without a CVE or detailed vulnerability information, detection and patching guidance is limited.
Urgency
🟠Within 24 hours
Recommended Actions
- Identify all DD-WRT routers in your environment and isolate them from critical network segments until patches are available
- Monitor DD-WRT router logs and network traffic for unusual outbound connections, scanning activity, or process execution patterns
- Implement network segmentation to limit potential lateral movement from compromised edge devices
- Check for indicators of compromise including unexpected processes, modified configurations, or connections to known Gafgyt C2 infrastructure
- Consider replacing DD-WRT firmware with vendor-supported alternatives if timely patches are not available
