CVE-2021-35394(realtek / rtl819x_jungle_software_development_kit)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-12-24. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rtl819x_jungle_software_development_kit

Threat summary

  • 15 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 13 mentions (2026-10-05); latest day: 2
  • 15 total mentions across 2 days

Affected systems

Vendors
Products
rtl819x_jungle_software_development_kit

Deep dive

Activity timeline15 mentions / 2d
0371013Mentions · 2026-10-05: 13Mentions · 2026-10-06: 210-0510-06
Referenced assets38 URLs
By indicator
Full discourse15 posts
  • The Hacker News@TheHackersNews

    🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet. Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

    7240821835.4K
    2.4M followersView on X
  • Hunt.io@Huntio

    🚩 Cling IoT Malware Uses Google STUN Traffic to Hide C2 https://cyberpress.org/cling-iot-malware-masquerades-as-google-stun/ Cling is a newly observed IoT botnet exploiting exposed devices through flaws including CVE-2021-35394. For C2, it sends repeated STUN requests to public servers and uses the STUN transaction ID field to receive commands. Those commands can trigger payload downloads, scanning, exploitation, TCP tunneling, proxying, or DDoS activity. Some packets even appeared to come from Google STUN infrastructure, likely through UDP source spoofing. #ThreatIntel #Botnet #CyberSecurity

    030124825
    7.6K followersView on X
  • DFIR Radar@DFIR_Radar

    Cling botnet disguises C2 inside STUN protocol traffic and spoofs Google's STUN service to hide commands, exploiting CVE-2021-35394 and six other IoT flaws to spread and launch DDoS attacks. Key findings: - Cling exploits CVE-2021-35394, an RCE in the Realtek Jungle SDK diagnostic component (compiled as UDPServer) found in routers, access points, repeaters, and embedded appliances that rarely receive firmware updates. The malware also carries exploit code for six additional CVEs: CVE-2014-8361 (Realtek SDK), CVE-2023-26801 (LB-LINK routers), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), CVE-2016-10372 (Eir D1000), CVE-2023-41011 (FiberHome/China Mobile), and CVE-2016-20016 (MVPower CCTV DVR), giving it a wide propagation surface across commodity networking and surveillance hardware. - The C2 design encodes operator commands inside STUN transaction IDs, sending traffic that resembles routine NAT-traversal exchanges from tools like Microsoft Teams, Zoom, and WebRTC browsers. Infected devices contact a hardcoded list of 13 STUN servers; one of them, confirmed operator-controlled at 145.249.115[.]184, receives bot registrations containing infection metadata and reachability info. - Commands appear to originate from an IP belonging to Google's stun.l[.]google[.]com service. Nozomi's analysis points to source-address spoofing through a network provider that does not validate source addresses. TTL differences between genuine STUN replies and command-bearing packets are one of the few network-level tells that something is wrong. - Observed commands included internet-wide scanning for additional vulnerable targets, TCP tunneling, proxying, and UDP/TCP flood attacks. Confirmed DDoS targets included a South Korean 🇰🇷 ISP, a University of Chicago cluster, and two Minecraft servers. - Host artifacts are concrete and huntable: malware copies named .cling, persistence entries written to init scripts, and a replaced wget binary with companion files named wget.r and wget.p. Because most compromised devices offer no EDR telemetry, these filesystem indicators and network-layer patterns are often the only evidence available. Detection priority: at the network layer, hunt for STUN Binding Requests sent at short, regular intervals with transaction IDs set to all zeros, and for non-STUN UDP datagrams directed at known STUN endpoints. At the host layer, scan internet-facing embedded devices for files named .cling, modified init scripts, and replaced wget binaries. Reputation alone cannot be trusted here as packets sourced from high-reputation infrastructure are exactly what the operator is manufacturing. The full IOC list and ATT&CK mapping are in the Nozomi Networks Labs report. #DFIR_Radar

    20032201
    2.0K followersView on X
  • Threat Landscape@LandscapeThreat

    Cling is turning STUN into an IoT botnet command-and-control channel. A report says the malware exploits CVE-2021-35394, with additional command-injection flaws targeting exposed routers, DVRs and other devices: CVE-2016-20016, CVE-2023-41011, CVE-2016-10372, CVE-2025-34037, CVE-2024-3721, CVE-2023-26801 and CVE-2014-8361. It persists through init scripts and replaces wget with a malware wrapper. Bots send periodic STUN Binding Requests with zeroed transaction IDs, followed by custom registration datagrams containing mapped ports and an infection-method tag. Researchers confirmed 145[.]249[.]115[.]184 received registrations and returned commands to an advertised port. STUN transaction ID fields encode scanning and exploitation, payload execution, TCP tunneling, proxying and DDoS commands. Some packets appeared to originate from an IP associated with Google STUN, with source-IP spoofing considered most likely. Flood instructions observed during monitoring targeted a South Korean ISP, the University of Chicago cluster and two Minecraft-related targets. Target metadata lists academia, the Republic of Korea and the United States. No actor attribution was provided. Detection artifacts include repeated zero-ID STUN requests, non-STUN datagrams sent to STUN endpoints, .cling files, init-script entries and replaced wget binaries. IOCs: hxxp://118[.]45[.]196[.]225:800/mipsel, hxxp://58[.]211[.]144[.]243:800/mipsel, hxxp://120[.]193[.]219[.]210:800/mipsel #Malware

    0103053
    90 followersView on X
  • DFIR Radar@DFIR_Radar

    Cling botnet exploits CVE-2021-35394 (CVSS 9.8) in Realtek Jungle SDK, abusing public STUN infrastructure to disguise C2 traffic as legitimate NAT-traversal activity across routers, DVRs, and embedded Linux devices. Key details: - Exploitation of CVE-2021-35394 spiked around September 5, 2026, delivering Cling (also tracked as ClingSTUN by Fortinet). The botnet embeds hard-coded exploits for seven CVEs used in self-propagation: CVE-2014-8361 (Realtek), CVE-2016-20016 (MVPower), CVE-2023-26801 (LB-LINK), CVE-2023-41011 (China 🇨🇳 Mobile/FiberHome), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), and CVE-2026-87827 (KGUARD DVR). Initial access spans a much wider set including D-Link, Tenda, Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887), TP-Link CVE-2023-1389, AVTECH CVE-2024-7029, and others. - The C2 mechanism is the standout: Cling sends STUN Binding Requests to 13 hard-coded servers every five seconds, using an all-zero transaction ID (a deliberate protocol deviation). It then sends custom UDP registration datagrams containing mapped ports and infection-source tags like realtek.selfrep or selfrep.router. Operator commands arrive embedded in the STUN transaction ID field. The controlled server 145.249.115[.]184 returns all-zero transaction IDs rather than echoing the request, the tell that it is operator-controlled. More striking: observed command packets originate from 74.125.250[.]129, an IP resolving to stun.l[.]google[.]com, making malicious replies visually indistinguishable from Google STUN responses. - Persistence is layered: the binary copies itself to /root/.cling and /usr/local/bin/.cling, then appends both paths to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot for SysV and BusyBox init survival. A secondary persistence method replaces the legitimate wget binary with the malware, relocating the original, so any legitimate process invoking wget executes the bot instead. Single-instance enforcement uses SO_REUSEADDR on port 33957. - Once established, Cling supports recursive scanning and worm-like spread, TCP tunnel spawn/stop, proxy launch/stop, and timed DoS floods. Observed flood targets include 112.151.157[.]222:8080, 192.170.240[.]137:53, and Minecraft servers at 23.81.40[.]193:25565 and 147.185.221[.]129:25565. Payloads are fetched via shell script downloaders for ARM, MIPS R3000, PowerPC, Intel 80386, and AMD X86-64, maximizing the range of vulnerable embedded hardware. Network defenders: hunt outbound UDP to port 3478 with zero-byte transaction IDs and flag UDP datagrams to public STUN servers that do not conform to RFC 5389 (non-random transaction IDs, oversized or non-standard payloads). On the host side, check for /root/.cling, /usr/local/bin/.cling, and modifications to /etc/inittab or rcS. Validate the wget binary hash against a known-good baseline: a replaced wget is a clean persistence indicator with no legitimate use case. Port 33957 bound with SO_REUSEADDR on a router or DVR is a direct Cling presence signal. Full IOC list is in the Nozomi Networks report. #DFIR_Radar

    10000170
    2.0K followersView on X
  • 🧠 مُخبر AI Mukhbir@dropy50

    🚨 بوتنت Cling تخفي أوامر التحكم في حركة STUN رُصد مهاجمون يستغلون ثغرة Realtek Jungle SDK (CVE-2021-35394) لنشر بوتنت تستخدم STUN للقيادة والثبات والانتشار والأنفاق وهجمات حجب الخدمة. أجهزة الشبكة غير المحدّثة قد تُخترق دون علم المستخدم. https://t.co/AF9ZEGmHnT

    1000031
    72 followersView on X
  • RST Cloud@rst_cloud

    #threatreport #LowCompleteness ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure | 05-10-2026 Source: https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure Key details below ↓ 💀Threats: Clingstun, 🎯Victims: Internet facing devices, Iot devices, Linux devices, Routers 🔓CVEs: CVE-2026-87827 \[[Vulners](https://vulners.com/cve/CVE-2026-87827)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-10915 \[[Vulners](https://vulners.com/cve/CVE-2024-10915)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2024-3721 \[[Vulners](https://vulners.com/cve/CVE-2024-3721)] - CVSS V3.1: *6.3*, - Vulners: Exploitation: True CVE-2019-7256 \[[Vulners](https://vulners.com/cve/CVE-2019-7256)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - nortekcontrol linear_emerge_essential_firmware (le1.00-06) CVE-2016-20016 \[[Vulners](https://vulners.com/cve/CVE-2016-20016)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - mvpower tv-7104he_firmware (1.8.4_115215b9) CVE-2024-32292 \[[Vulners](https://vulners.com/cve/CVE-2024-32292)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda w30e_firmware (1.0.1.25\(633\)) CVE-2021-35394 \[[Vulners](https://vulners.com/cve/CVE-2021-35394)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - realtek rtl819x_jungle_software_development_kit (le3.4.14b) CVE-2024-32281 \[[Vulners](https://vulners.com/cve/CVE-2024-32281)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac7_firmware (15.03.06.44) CVE-2024-32314 \[[Vulners](https://vulners.com/cve/CVE-2024-32314)] - CVSS V3.1: *3.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac500_firmware (2.0.1.9\(1307\)) CVE-2025-67038 \[[Vulners](https://vulners.com/cve/CVE-2025-67038)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lantronix eds5008_firmware (<2.2.0.0r1) CVE-2024-46048 \[[Vulners](https://vulners.com/cve/CVE-2024-46048)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda fh451_firmware (1.0.0.9) CVE-2023-26801 \[[Vulners](https://vulners.com/cve/CVE-2023-26801)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lb-link bl-lte300_firmware (1.0.8) CVE-2022-37055 \[[Vulners](https://vulners.com/cve/CVE-2022-37055)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink go-rt-ac750_firmware (2.00b02) CVE-2023-41011 \[[Vulners](https://vulners.com/cve/CVE-2023-41011)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - chinamobile intelligent_home_gateway_firmware (hg6543c4) CVE-2022-35555 \[[Vulners](https://vulners.com/cve/CVE-2022-35555)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - tenda w6_firmware (1.0.0.9\(4122\)) CVE-2024-10914 \[[Vulners](https://vulners.com/cve/CVE-2024-10914)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2023-1389 \[[Vulners](https://vulners.com/cve/CVE-2023-1389)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - tp-link archer_ax21_firmware (<1.1.4) CVE-2024-7029 \[[Vulners](https://vulners.com/cve/CVE-2024-7029)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - avtech avm1203_firmware (lefullimg-1023-1007-1011-1009) CVE-2025-34035 \[[Vulners](https://vulners.com/cve/CVE-2025-34035)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - engeniustech esr300_firmware (1.1.0.28, 1.3.1.42, 1.4.0, 1.4.1.28, 1.4.2) CVE-2024-23624 \[[Vulners](https://vulners.com/cve/CVE-2024-23624)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2022-36553 \[[Vulners](https://vulners.com/cve/CVE-2022-36553)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - hytec hwl-2511-ss_firmware (le1.05) CVE-2019-17621 \[[Vulners](https://vulners.com/cve/CVE-2019-17621)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-859_firmware (le1.05b03, 1.06b01) CVE-2026-36356 \[[Vulners](https://vulners.com/cve/CVE-2026-36356)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True CVE-2025-34037 \[[Vulners](https://vulners.com/cve/CVE-2025-34037)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-23625 \[[Vulners](https://vulners.com/cve/CVE-2024-23625)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2024-35340 \[[Vulners](https://vulners.com/cve/CVE-2024-35340)] - CVSS V3.1: *8.6*, - Vulners: Exploitation: Unknown Soft: - tenda fh1206_firmware (1.2.0.8\(8155\)) CVE-2023-46805 \[[Vulners](https://vulners.com/cve/CVE-2023-46805)] - CVSS V3.1: *8.2*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2024-21887 \[[Vulners](https://vulners.com/cve/CVE-2024-21887)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2022-26289 \[[Vulners](https://vulners.com/cve/CVE-2022-26289)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda m3_firmware (1.0.0.12\(4856\)) CVE-2014-8361 \[[Vulners](https://vulners.com/cve/CVE-2014-8361)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-905l_firmware (le2.05b01) CVE-2021-36380 \[[Vulners](https://vulners.com/cve/CVE-2021-36380)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - sunhillo sureline (<8.7.0.1.1) 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036, T1037, T1057, T1071, T1090, T1105, T1190, T1547, T1564 🧨IOCs: - IP: 3 - File: 5 - Hash: 21 💽Software: Linux, WebRTC, Ivanti, Tenda, LB-LINK 💻Platforms: mips, arm, intel #threatreport: ClingSTUN is a Linux backdoor that exploits Internet-facing, unpatched devices and converts them into remotely controlled proxy nodes. Initial delivery was observed through exploitation of CVE-2022-36553, a command-injection vulnerability in Hytec Inter HWL-2511-SS routers. Subsequent campaigns used command injection in the EnGenius IoT cloud service (CVE-2025-34035), D-Link UPnP (CVE-2024-23625), Linear and other IoT devices, Realtek devices affected by CVE-2021-35394, TP-Link Archer AX21 devices affected by CVE-2023-1389, AVTECH AVM1203 devices affected by CVE-2024-7029, and D-Link devices affected by CVE-2024-10915. The attackers also used a buffer overflow in the `goform` name parameter across multiple device vendors. ClingSTUN downloaders move to `/tmp`, retrieve architecture-specific payloads, and execute versions for ARM, Intel 80386, MIPS, PowerPC, and AMD x86-64 systems. A later downloader scans `/proc/mounts`, unmounts selected mount points, kills associated processes, and terminates processes running from `/tmp`. The malware also enumerates `/proc`, identifies competing or suspicious processes, compares process command lines with executable names, and kills processes that fail its checks. It opens watchdog device files and uses `ioctl` to disable watchdog timers. For persistence, ClingSTUN copies itself to `/root/.cling` and `/usr/local/bin/.cling`, sets executable permissions, and appends these files to three startup-related files so they execute during boot. It clears its command-line arguments to hide activity from process-monitoring tools. When running as root, it copies selected files from `/proc/1` into `/tmp` and bind-mounts the directory over its own `/proc` entry to conceal process information. The backdoor uses UDP sockets and standard 20-byte STUN binding requests to contact public STUN services, discover externally mapped addresses and ports, and maintain NAT bindings. Earlier versions contacted 24 endpoints and required at least half to respond; a later version used 13 endpoints and required all to succeed. It periodically sends a group identifier and mapped-port data to these services. A specially formatted 20-byte operator packet can trigger remote command execution: command 1 causes the malware to establish an outbound TCP connection, receive a command, and execute it. ClingSTUN also contains hard-coded exploits for self-propagation.

    0000093
    829 followersView on X
  • SecureChap@SecureChap

    Zeroed transaction IDs inside routine STUN Binding Requests are how this Cling implant receives its orders. The binary lands via CVE-2021-35394 and immediately drops eight more router and DVR exploits for lateral movement. Observed targets include Realtek SDK devices hit by CVE-2014-8361 and CVE-2016-10372 plus recent TP-Link and Netgear flaws. Twenty-five additional initial-access CVEs appear in the same campaigns. Persistence is simple and effective. Cling writes copies to /root/.cling and /usr/local/bin/.cling, then appends itself to /etc/inittab, /etc/init.d/rcS and /etc/rc.d/rc.boot so it survives reboot. C2 runs over the same UDP socket that opens with SO_REUSEADDR on port 33957. Every five seconds it fires a STUN Binding Request to one of thirteen hardcoded servers; the operator stuffs commands into the normally random transaction ID field while the rest of the packet stays standard. One server at 145.249.115.184 answers with all-zero IDs, commands arrive from 74.125.250.129, and the implant registers itself the same way. The STUN disguise makes the traffic blend with legitimate NAT traversal until you start inspecting the TXID field.

    0000020
    174 followersView on X
  • P.K. Sharma@_pksharma

    Cling botnet poses as STUN traffic, but gets in through flaws catalogued up to 4,175 days ago The oldest flaw named in the two reports on the Cling botnet has a CVE record from 1 May 2015. Counted to 5 October 2026, that is 4,175 days. Nozomi Networks says the malware sends commands in packets shaped like STUN, the protocol that helps video calls cross routers. The way in is not new. 🧮 Between Nozomi's post and FortiGuard's, 32 distinct flaws are named (8 and 31, with 7 in both). 10 of the 32 are in CISA's exploited catalogue and 22 are not. 22 of the 32 records predate the UK's consumer product security rules, in force from 29 April 2024. CVE-2021-35394, behind Nozomi's spike, has been in the catalogue since 10 December 2021: 1,760 days (derived). 🔍 Cling and ClingSTUN overlap but are not one sample: the same hidden copies and init files, and all 13 of Nozomi's STUN servers sit among FortiGuard's 24. Each lists seven spread exploits and shares six. Neither report gives a victim count, an operator or a UK figure, and neither says the traffic cannot be detected. Nozomi lists tells, including transaction IDs of all zeros where the standard requires random ones. ⚖️ A firewall rule that allows STUN allows whoever speaks STUN, and a source address on a UDP packet is a claim, not an identity. Order of work: list every edge device with its support end date, retire what is out of support, patch what can be patched, then restrict outbound STUN from device VLANs unless a service needs it. That last step is our judgement and breaks some calls. Replace rather than clean. 🔑 If a router at one of your branch sites were compromised tonight and produced only traffic that looked like a video call, which list in your organisation would tell you it was there? Full briefing: https://www.pk-sharma.com/briefing/cling-botnet-poses-as-stun-but-enters-through-flaws-up-to-4175-days-old #Cling #Botnet #STUN #IoTSecurity #Nozomi #FortiGuard #PSTI #EndOfLife #ThreatIntel #InfoSec #CyberSecurity #CISO #SecOps #UKTech

    0000031
    192 followersView on X
  • UnpanicTech@unpanictech

    https://www.unpanictech.online/2026/10/cling-botnet-realtek-cve-2021-35394-stun-c2.html

    0000013
    16 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis reveals Cling botnet operators disguised C2 traffic as legitimate Google STUN communications, exploiting CVE-2021-35394 in Realtek SDK. Attackers performed recursive scanning across infected IoT devices to expand the botnet. Runtime segmentation helps contain lateral movement in compromised device networks. #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/realtek-jungle-sdk-cling-botnet-stun-c2-2026

    0000036
    2.0K followersView on X
  • NeoTeo.com@NeoteoCom

    Cling esconde comandos C2 dentro de tráfico STUN y explota el fallo Realtek Jungle SDK CVE-2021-35394 para propagarse como botnet. Túneles, proxies y DoS sobre la misma sesión legítima. https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

    00000117
    15.9K followersView on X
  • Anthony Mongeluzo@PCS_AnthonyM

    @TheHackersNews Hiding C2 inside STUN traffic while riding Realtek Jungle SDK CVE-2021-35394. Cling's botnet path is a reminder that "normal" NAT-traversal packets still deserve a second look on the wire.

    0000068
    6.8K followersView on X
  • The Daily Tech Feed@dailytechonx

    Cling botnet exploits Realtek Jungle SDK’s CVE-2021-35394 to execute remote code and leverages STUN traffic as a stealth C2 channel. Abuse spans routers, DVRs, and disguise tactics like replacing wget and hijacking init. Keeping firmware updated and monitoring unusual STUN behavior are now essential keywords in IoT security. #IoTSecurity #Botnet #Realtek #STUN #Cling #CyberThreat https://thedailytechfeed.com/cling-botnet-misuses-realtek-jungle-sdk-rce-via-stun-based-c2/

    0000038
    778 followersView on X
  • ByteCheck@ByteCheck101

    🚨 Realtek SDK Exploits Fuel Cling Botnet Threat actors are exploiting CVE-2021-35394 (CVSS 9.8), a critical RCE flaw in Realtek Jungle SDK, to deploy the Cling botnet. What makes Cling stand out? It abuses legitimate-looking STUN traffic for command-and-control, helping its activity blend into normal NAT-traversal traffic. Cling can: • Spread across vulnerable routers & DVRs • Maintain persistence on infected devices • Proxy & tunnel traffic • Scan for additional targets • Launch DoS attacks • Receive C2 commands through STUN transaction data Nozomi Networks observed exploitation attempts surging from September 5, 2026. #CyberSecurity #Botnet #Malware #IoT #Realtek #ThreatIntel #InfoSec #ThreatActor

    0000058
    17 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apprealtekrtl819x_jungle_software_development_kit---

Explore more