CVE-2016-10372Active Exploitation(eir / d1000_modem)

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for eir d1000_modem systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the Wi-Fi password), and using the NewNTPServer feature.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-264

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • d1000_modem
  • d1000_modem_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Peaked 1d ago at 2 mentions (2026-10-05); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
d1000_modemd1000_modem_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-14: 1Mentions · 2026-10-05: 2Mentions · 2026-10-06: 1Active Exploitation · 2026-02-14: 102-1410-0510-06
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse4 posts
  • DFIR Radar@DFIR_Radar

    Cling botnet disguises C2 inside STUN protocol traffic and spoofs Google's STUN service to hide commands, exploiting CVE-2021-35394 and six other IoT flaws to spread and launch DDoS attacks. Key findings: - Cling exploits CVE-2021-35394, an RCE in the Realtek Jungle SDK diagnostic component (compiled as UDPServer) found in routers, access points, repeaters, and embedded appliances that rarely receive firmware updates. The malware also carries exploit code for six additional CVEs: CVE-2014-8361 (Realtek SDK), CVE-2023-26801 (LB-LINK routers), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), CVE-2016-10372 (Eir D1000), CVE-2023-41011 (FiberHome/China Mobile), and CVE-2016-20016 (MVPower CCTV DVR), giving it a wide propagation surface across commodity networking and surveillance hardware. - The C2 design encodes operator commands inside STUN transaction IDs, sending traffic that resembles routine NAT-traversal exchanges from tools like Microsoft Teams, Zoom, and WebRTC browsers. Infected devices contact a hardcoded list of 13 STUN servers; one of them, confirmed operator-controlled at 145.249.115[.]184, receives bot registrations containing infection metadata and reachability info. - Commands appear to originate from an IP belonging to Google's stun.l[.]google[.]com service. Nozomi's analysis points to source-address spoofing through a network provider that does not validate source addresses. TTL differences between genuine STUN replies and command-bearing packets are one of the few network-level tells that something is wrong. - Observed commands included internet-wide scanning for additional vulnerable targets, TCP tunneling, proxying, and UDP/TCP flood attacks. Confirmed DDoS targets included a South Korean 🇰🇷 ISP, a University of Chicago cluster, and two Minecraft servers. - Host artifacts are concrete and huntable: malware copies named .cling, persistence entries written to init scripts, and a replaced wget binary with companion files named wget.r and wget.p. Because most compromised devices offer no EDR telemetry, these filesystem indicators and network-layer patterns are often the only evidence available. Detection priority: at the network layer, hunt for STUN Binding Requests sent at short, regular intervals with transaction IDs set to all zeros, and for non-STUN UDP datagrams directed at known STUN endpoints. At the host layer, scan internet-facing embedded devices for files named .cling, modified init scripts, and replaced wget binaries. Reputation alone cannot be trusted here as packets sourced from high-reputation infrastructure are exactly what the operator is manufacturing. The full IOC list and ATT&CK mapping are in the Nozomi Networks Labs report. #DFIR_Radar

    20032399
    2.0K followersView on X
  • Threat Landscape@LandscapeThreat

    Cling is turning STUN into an IoT botnet command-and-control channel. A report says the malware exploits CVE-2021-35394, with additional command-injection flaws targeting exposed routers, DVRs and other devices: CVE-2016-20016, CVE-2023-41011, CVE-2016-10372, CVE-2025-34037, CVE-2024-3721, CVE-2023-26801 and CVE-2014-8361. It persists through init scripts and replaces wget with a malware wrapper. Bots send periodic STUN Binding Requests with zeroed transaction IDs, followed by custom registration datagrams containing mapped ports and an infection-method tag. Researchers confirmed 145[.]249[.]115[.]184 received registrations and returned commands to an advertised port. STUN transaction ID fields encode scanning and exploitation, payload execution, TCP tunneling, proxying and DDoS commands. Some packets appeared to originate from an IP associated with Google STUN, with source-IP spoofing considered most likely. Flood instructions observed during monitoring targeted a South Korean ISP, the University of Chicago cluster and two Minecraft-related targets. Target metadata lists academia, the Republic of Korea and the United States. No actor attribution was provided. Detection artifacts include repeated zero-ID STUN requests, non-STUN datagrams sent to STUN endpoints, .cling files, init-script entries and replaced wget binaries. IOCs: hxxp://118[.]45[.]196[.]225:800/mipsel, hxxp://58[.]211[.]144[.]243:800/mipsel, hxxp://120[.]193[.]219[.]210:800/mipsel #Malware

    0103065
    106 followersView on X
  • SecureChap@SecureChap

    Zeroed transaction IDs inside routine STUN Binding Requests are how this Cling implant receives its orders. The binary lands via CVE-2021-35394 and immediately drops eight more router and DVR exploits for lateral movement. Observed targets include Realtek SDK devices hit by CVE-2014-8361 and CVE-2016-10372 plus recent TP-Link and Netgear flaws. Twenty-five additional initial-access CVEs appear in the same campaigns. Persistence is simple and effective. Cling writes copies to /root/.cling and /usr/local/bin/.cling, then appends itself to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot so it survives reboot. C2 runs over the same UDP socket that opens with SO_REUSEADDR on port 33957. Every five seconds it fires a STUN Binding Request to one of thirteen hardcoded servers; the operator stuffs commands into the normally random transaction ID field while the rest of the packet stays standard. One server at 145.249.115.184 answers with all-zero IDs, commands arrive from 74.125.250.129, and the implant registers itself the same way. The STUN disguise makes the traffic blend with legitimate NAT traversal until you start inspecting the TXID field.

    0000032
    175 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2016-10372 — CHINA UNICOM China169 Backbone Visit -- https://cti.loginsoft.com/ip/14.205.104.200 #Loginsoft #Cytellite #Cybersecurity #CVE201610372 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/lJixrTbZ2p

    Post summary

    Cytellite reports recent detection of activity targeting CVE-2016-10372 on a CHINA UNICOM China169 backbone IP, indicating ongoing exploitation, but no PoC, exploit code, patch, or technical details are provided.

    0000035
    19 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWeird1000_modem---
OSeird1000_modem_firmware---

Explore more