Back to Blog
CVE-2007-3010 et al.: Multiple Vendors Edge Devices — Proxy Botnet Takeover Risk (July 2026)
vulnerabilities

CVE-2007-3010 et al.: Multiple Vendors Edge Devices — Proxy Botnet Takeover Risk (July 2026)

breachwire TeamAug 23, 20262 min read

CVE-2007-3010 et al. — Multi-Vendor Edge Devices

Evooo1Bot, a Mirai-variant Linux botnet, is actively exploiting 18 known vulnerabilities including CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, CVE-2025-55583, CVE-2021-36260, CVE-2022-26134, CVE-2022-29464, CVE-2022-30525, CVE-2023-1389, CVE-2024-4577, CVE-2024-10914, and CVE-2025-1974. These high-severity flaws enable attackers to compromise publicly accessible Linux-based edge devices, converting them into SOCKS5 proxies for malicious traffic and further attacks. All listed CVEs are confirmed as actively exploited in the wild.

Attack Vector

Attackers scan for vulnerable edge devices exposed to the internet, leveraging exploits for the above CVEs to gain remote code execution or administrative access. Once compromised, devices download and execute a payload (e.g., via wget.sh from 91.92.40.118), enrolling them into the Evooo1Bot network. The botnet supports commands for DDoS attacks, SSH brute force, and further exploitation, using infected devices as proxy nodes to mask malicious activity and evade detection.

Who Is at Risk

Any organization operating Linux-based edge devices (routers, IoT gateways, NAS, and similar) with unpatched firmware or software versions corresponding to the listed CVEs is at risk. Devices from multiple vendors are impacted; specific models depend on each CVE. All geographies are affected due to the global scanning and exploitation campaign. No confirmed victim organizations are named, but exposure is widespread.

Patch & Mitigate

  • Patch: Apply vendor security updates addressing all listed CVEs immediately. Prioritize internet-facing devices and those running outdated firmware. No universal hotfix; consult vendor advisories for each CVE.
  • Workaround: Restrict device management interfaces to trusted networks, disable unused services, and enforce strong authentication where possible.
  • Detect: Monitor for outbound connections to 91.92.40.118 and suspicious shell script downloads (e.g., wget.sh). Review logs for unauthorized access, unexpected SOCKS5 proxy activity, and brute-force attempts.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploit remote services and vulnerabilities to gain entry.
  • TA0005 — Defense Evasion: Compromised devices are used as proxies to mask attacker infrastructure.
  • TA0011 — Command and Control: Infected devices maintain communication with botnet C2 for ongoing control and tasking.

Source: https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: