CVE-2016-5681Active Exploitation(d-link / dir-817l\(w\))

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch d-link dir-817l\(w\) systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-817l\(w\)
  • dir-817l\(w\)_firmware
  • dir-818l\(w\)
  • dir-818l\(w\)_firmware

Threat summary

  • Active exploitation appears in 6 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-06-22); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
dir-817l\(w\)dir-817l\(w\)_firmwaredir-818l\(w\)dir-818l\(w\)_firmwaredir-822dir-822_firmwaredir-823dir-823_firmwaredir-850ldir-850l_firmare

5 versions affected across 20 products

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-06-18: 1Mentions · 2026-06-21: 1Mentions · 2026-06-22: 5Mentions · 2026-06-29: 1Exploit Tool / Code · 2026-06-22: 2Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-06-22: 3Active Exploitation · 2026-06-29: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 106-1806-2106-2206-29
Signal classification3 categories
Active Exploitation
562.5%
Exploit
225.0%
General
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-181
Active Exploitation1
2026-06-211
Active Exploitation1
2026-06-225
Active Exploitation2Exploit2General1
2026-06-291
Active Exploitation1
Full discourse8 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    الاستهداف مركز على راوترات D-Link القديمة: 📍 DIR-850L 📍 DIR-818LW ويستغل ثغرات مثل: 📍 CVE-2013-3307 📍 CVE-2016-5681 📍 CVE-2025-11837

    Post summary

    The post identifies targeted D-Link router models and references three CVEs but offers no further exploitation, patch, or technical details.

    100501.3K
    50.1K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    AryStinger a new botnet has turned 4,000+ end-of-life D-Link routers (DIR-850L, DIR-818LW) into distributed attack proxies. Exploits: CVE-2013-3307, CVE-2016-5681, CVE-2025-11837. Infected devices scan, proxy, tunnel, hijack DNS, and sniff all traffic. A second Go variant targets NAS, running Shell/Go/Java/Python payloads. 48% of infections sit in South Korea. No attribution to any known cluster. The hardware is EoL no patch is coming. Replace it and kill remote management. Source: @BleepinComputer @VulnerabilityNw

    Post summary

    AryStinger leverages several CVEs to compromise end‑of‑life D‑Link routers, turning them into active proxy and scanning devices. No patches exist, so the only mitigative action is hardware replacement.

    0101082
    184 followersView on X
  • connect24h@connect24h
    Exploit

    D-Linkルータ4000台超がproxy化、日本ではどうなんだ?AryStingerは古いDIR-850L/DIR-818LWをCVE-2013-3307、CVE-2016-5681、CVE-2025-11837で突き、scan、tunneling、DNS改ざんまでやる。現場はEoL機器、外部公開の管理画面、DNS設定、怪しいproxy通信を要調査。ただ、個人宅だとISP対応かな。 #セキュリティ https://is.gd/pbCad8

    Post summary

    The post reports that older D‑Link routers are vulnerable to multiple CVEs and can be targeted using the AryStinger tool, which performs scanning, tunneling, and DNS hijacking, but it offers no patch guidance or in-the-wild evidence.

    00011269
    3.7K followersView on X
  • كاسبر سكاي@KasperskyDev
    Active Exploitation

    برمجية خبيثة سيطرت على أكثر من 4300 راوتر دي لنك وجهاز تخزين شبكي وحوّلتها إلى بروكسيات للمسح وتصفح الغارة البرمجية : AryStinger طريقة الاختراق : Exploiting CVE-2013-3307 and CVE-2016-5681 حجم التأثير : 4300+ routers worldwide #Botnet #DLink #CyberSecurity

    Post summary

    Malware AryStinger exploited CVE-2013-3307 and CVE-2016-5681 to compromise over 4,300 D-Link routers worldwide, converting them into scanning and proxy resources for further attacks.

    01000234
    40.0K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    AryStinger malware turns 4,300+ end-of-life Realtek RTL819X routers into a distributed reconnaissance botnet, exploiting CVEs from 2013 and 2016 with zero VirusTotal detections at discovery. - Initial access via CVE-2013-3307 and CVE-2016-5681, both over a decade old, spreading a C-based ELF binary from 107.150.106[.]45. The C build persists by dropping Dropbear SSH on port 2332 and communicates via HTTP with Protobuf traffic XOR-encrypted using the hardcoded key sh_#@!_2024_secret, suggesting the op predates the March 12, 2026 detection. - A Go-based second build targets QNAP NAS devices via CVE-2025-11837, patched November 2025 and exploited within five months. It integrates fscan, ksubdomain, httpx, and Tlsx, plus a ScriptWork engine that executes attacker-supplied Go, Java, or Python source directly on device, dropping plaintext payloads to disk. - The fleet operates as an ORB network: each Executor node receives a scan slice, runs it in parallel, and returns results, masking true operator origin. D-Link DIR-850L accounts for ~75% of infected devices. - C2 and download infrastructure uses ajb8[.]com, dataexplore[.]cc, and dataexplore[.]co. Watch for processes named syswapd0h or syswapd0w and unexpected binaries in /tmp/bin. Hunt outbound connections to those three domains, check /tmp/bin, and audit for Dropbear SSH on port 2332. #DFIR_Radar

    Post summary

    The post reports an actively exploited botnet that leverages multiple legacy CVEs and includes functional exploit binaries, with a vendor patch already released.

    10000253
    1.7K followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 NEW: AryStinger — a previously undocumented botnet — has compromised 4,000+ D-Link routers (DIR-850L, DIR-818LW) by exploiting end-of-life vulnerabilities: CVE-2013-3307, CVE-2016-5681, CVE-2025-11837. Infected routers become distributed scanning proxies, tunnels, and command executors for follow-on intrusion operations. The genius: AryStinger splits massive scanning tasks into parallel chunks across compromised routers, covering their tracks in the process. 48.5% of infections are in South Korea, 31.8% China, with secondary clusters in Sweden, Malaysia, Singapore. A Go-based variant also targets NAS systems. The same router models were previously hit by AVrecon. If you own a D-Link DIR-850L or DIR-818LW, assume it’s compromised. Replace it now. Full breakdown 👇 https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/

    Post summary

    AryStinger is actively exploiting multiple end‑of‑life vulnerabilities (CVE‑2013‑3307, CVE‑2016‑5681, CVE‑2025‑11837) in D‑Link routers, compromising thousands of devices that are now co‑opted into a botnet used for scanning, tunneling, and command execution.

    1000092
    85 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    AryStinger malware exploited decade-old vulnerabilities (CVE-2013-3307, CVE-2016-5681) to compromise 4,300 legacy routers, transforming them into a distributed reconnaissance network. Infected devices scan internal networks and tunnel malicious traffic, complicating attribution. Runtime segmentation could help contain such lateral movement from compromised edge infrastructure. #ThreatIntel :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/arystinger-malware-infects-4300-legacy-routers-2026

    Post summary

    The analysis confirms that AryStinger malware actively exploited CVE‑2013‑3307 and CVE‑2016‑5681 to compromise thousands of legacy routers, turning them into a reconnaissance network.

    0000058
    1.9K followersView on X
  • Meridian Group@MeridianEU
    Active Exploitation

    #AryStinger botnet compromised 4,000+ legacy D-Link routers and NAS devices via CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. Infected devices used as proxy infrastructure to mask secondary malicious activity. Opportunistic targeting focused on end-of-life hardware. https://t.co/umW9gf0hzS

    Post summary

    AryStinger botnet leveraged CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 to infect thousands of legacy D‑Link routers and NAS devices, using them as proxy infrastructure for illicit activity.

    00000130
    60 followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
OSd-linkdir-817l\(w\)_firmware---
OSd-linkdir-818l\(w\)_firmware---
OSd-linkdir-823_firmware---
OSd-linkdir-850l_firmare---
OSd-linkdir-880l_firmware---
OSd-linkdir-885l_firmware---
OSd-linkdir-890l_firmware---
OSd-linkdir-895l_firmware---
HWdlinkdir-817l\(w\)ax--
HWdlinkdir-818l\(w\)ax--
HWdlinkdir-822a1--
OSdlinkdir-822_firmware3.01--
HWdlinkdir-823a1--
HWdlinkdir-850lb1--
HWdlinkdir-868lb1--
HWdlinkdir-868lc1--
OSdlinkdir-868l_firmware---
HWdlinkdir-880la1--
HWdlinkdir-885la1--
HWdlinkdir-890la1--
HWdlinkdir-895la1--

Explore more