CVE-2024-3721Active Exploitation

CRITICALCVSS 6.3 · MEDIUM

Exploitation observed; activity peaked at 33 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___. The manipulation of the argument mdb/mdc leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260573 was assigned to this vulnerability.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 64 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 74 mentions across 12 observed days

What's happening

  • Active exploitation reported across 64 signals
  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 14 signals
  • General: 2 classified signals
  • Peaked 9d ago at 33 mentions (2026-04-18); latest day: 1
  • 74 total mentions across 12 days

Deep dive

Activity timeline74 mentions / 12d
08172533Mentions · 2026-03-27: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 33Mentions · 2026-04-19: 14Mentions · 2026-04-20: 14Mentions · 2026-04-21: 3Mentions · 2026-04-22: 1Mentions · 2026-05-09: 1Mentions · 2026-08-02: 1Mentions · 2026-10-05: 2Mentions · 2026-10-06: 2Mentions · 2026-10-10: 1PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-08-02: 1Exploit Tool / Code · 2026-04-18: 2Exploit Tool / Code · 2026-04-19: 1Exploit Tool / Code · 2026-08-02: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-18: 31Active Exploitation · 2026-04-19: 14Active Exploitation · 2026-04-20: 14Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-05-09: 1Active Exploitation · 2026-08-02: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-18: 3Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-20: 2Patch / Workaround · 2026-04-21: 3Technical Details · 2026-03-27: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 3Technical Details · 2026-04-19: 3Technical Details · 2026-04-20: 4Technical Details · 2026-05-09: 1Technical Details · 2026-08-02: 103-2704-1704-1804-1904-2004-2104-2205-0908-0210-0510-0610-10
Signal classification5 categories
Active Exploitation
6289.9%
General
22.9%
Exploit
22.9%
Patch
22.9%
Disclosure
11.4%
Referenced assets67 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-271
General1
2026-04-171
Active Exploitation1
2026-04-1833
Active Exploitation30Disclosure1Exploit2
2026-04-1914
Active Exploitation14
2026-04-2014
Active Exploitation14
2026-04-213
Active Exploitation1Patch2
2026-04-221
General1
2026-05-091
Active Exploitation1
2026-08-021
Active Exploitation1
Full discourse20 posts
  • Germán Fernández@1ZRR4H
    General

    🔸 45[.]137[.]70[.]27:8080 #opendir 🔎 → CVE-2026-24061 (Telnetd Auth Bypass) → CVE-2024-3721 (TBK DVR Command Injection) → CVE-2024-10443 (Synology RCE via Crontab) https://t.co/ybGabCZnj3

    Post summary

    The post enumerates three CVEs with short descriptive names but does not supply exploitation or mitigation details.

    020095638.4K
    37.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    Attackers are exploiting CVE-2024-3721 in TBK DVRs to deploy Mirai variant Nexcorium. It spreads via old exploits and default creds, persists on devices, and launches DDoS attacks. EoL TP-Link routers are also being targeted via known flaws. 🔗 Read → https://thehackernews.com/2026/04/mirai-variant-nexcorium-exploits-cve.html

    Post summary

    Attackers are actively exploiting CVE-2024-3721 in TBK DVRs to deploy a Mirai variant, using old exploits and default credentials, enabling DDoS attacks and also targeting EoL TP‑Link routers.

    5192621210.9K
    1.8M followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    A recent campaign exploiting CVE-2024-3721 in TBK DVR devices to deliver a multi-architecture Mirai variant called Nexcorium #botnet https://www.fortinet.com/blog/threat-research/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign https://t.co/sDAO6tiW9U

    Post summary

    The tweet reports an active campaign that exploits CVE-2024-3721 in TBK DVR devices to deploy a Mirai variant named Nexcorium.

    1702383.0K
    42.7K followersView on X
  • Imad Khan@Imad_khan09
    Active Exploitation

    🚨 New IoT Threat Alert A Mirai variant called Nexcorium is actively exploiting CVE-2024-3721 to hijack TBK DVR devices and turn them into DDoS botnets. https://t.co/pIrAYyTg1c

    Post summary

    The tweet reports that a Mirai variant named Nexcorium is actively exploiting CVE-2024‑3721 to hijack TBK DVR devices and create a DDoS botnet.

    75092152
    41 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    FortiGuard unmasks Nexcorium, a Mirai variant targeting DVRs via CVE-2024-3721. Secure your IoT devices against this multi-arch DDoS botnet. Patch now! #Nexcorium #IoTSecurity #Mirai #Botnet #DDoS #NexusTeam #CyberSecurity #IoT https://securityonline.info/nexcorium-mirai-variant-dvr-botnet-nexus-team/ https://t.co/kbDh5Yx1az

    Post summary

    The tweet reveals a Mirai variant (Nexcorium) exploiting CVE-2024-3721 in DVRs and urges readers to patch their IoT devices against the multi‑arch DDoS botnet.

    15097788
    12.5K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 Nexcorium Mirai variant exploits CVE-2024-3721 to hijack IoT devices for DDoS botnet Command injection + multi-arch payload + brute-force spread → persistent large-scale botnet 💡 Lesson: Modern botnets = exploit + credential abuse + persistence ⚠️ Action: Patch CVEs, replace EoL devices, disable default creds/Telnet https://securityaffairs.com/190974/malware/nexcorium-mirai-variant-exploits-tbk-dvr-flaw-to-launch-ddos-attacks.html

    Post summary

    The text reports that a Nexcorium Mirai variant is actively exploiting CVE‑2024‑3721 to hijack IoT devices for a large‑scale DDoS botnet, emphasizing command injection and credential abuse, and urges prompt patching and disabling default credentials.

    0401141.3K
    16.1K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    🚨 Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack IoT Devices for DDoS Botnet DVR command injection + EoL router abuse + brute-force → large-scale botnet expansion 💡 Lesson: Unpatched IoT + default creds = persistent botnet ecosystem ⚠️ Action: Replace EoL devices, patch known CVEs, disable Telnet/default creds https://thehackernews.com/2026/04/mirai-variant-nexcorium-exploits-cve.html

    Post summary

    The Mirai variant Nexcorium is actively exploiting CVE‑2024‑3721 on unpatched IoT devices via command injection, underscoring the need to replace end‑of‑life hardware and patch the vulnerability promptly.

    0301031.1K
    16.1K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet https://thehackernews.com/2026/04/mirai-variant-nexcorium-exploits-cve.html

    Post summary

    The headline reports that a Mirai variant is actively exploiting CVE‑2024‑3721 to hijack TBK DVRs for a DDoS botnet.

    1401001.7K
    158.1K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    Fortinet reports that Nexcorium targets TBK DVRs with exploitation, persistence, brute-force, and multi-architecture Mirai-style DDoS, leveraging CVE-2024-3721 and CVE-2017-17215 to illustrate rapid IoT threat evolution. https://www.fortinet.com/blog/threat-research/tracking-mirai-variant-nexcorium-a-vulnerability-driven-iot-botnet-campaign

    Post summary

    Fortinet’s report notes that the Nexcorium botnet is actively exploiting TBK DVRs using CVE‑2024‑3721 and CVE‑2017‑17215 to facilitate brute‑force access and Mirai‑style DDoS attacks, underscoring ongoing IoT threat evolution.

    03051782
    22.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Nexcorium Mirai variant exploits CVE-2024-3721 in TBK DVRs and end-of-life TP-Link routers for DDoS botnet expansion. Multi-architecture malware uses XOR encoding and embeds CVE-2017-17215 exploits. #DFIR_Radar https://t.co/s8rwl3TQkG

    Post summary

    The Nexcorium Mirai variant is actively exploiting CVE‑2024‑3721 on TBK DVRs and end‑of‑life TP‑Link routers to expand its DDoS botnet.

    11051383
    1.7K followersView on X
  • DFIR Radar@DFIR_Radar

    Cling botnet disguises C2 inside STUN protocol traffic and spoofs Google's STUN service to hide commands, exploiting CVE-2021-35394 and six other IoT flaws to spread and launch DDoS attacks. Key findings: - Cling exploits CVE-2021-35394, an RCE in the Realtek Jungle SDK diagnostic component (compiled as UDPServer) found in routers, access points, repeaters, and embedded appliances that rarely receive firmware updates. The malware also carries exploit code for six additional CVEs: CVE-2014-8361 (Realtek SDK), CVE-2023-26801 (LB-LINK routers), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), CVE-2016-10372 (Eir D1000), CVE-2023-41011 (FiberHome/China Mobile), and CVE-2016-20016 (MVPower CCTV DVR), giving it a wide propagation surface across commodity networking and surveillance hardware. - The C2 design encodes operator commands inside STUN transaction IDs, sending traffic that resembles routine NAT-traversal exchanges from tools like Microsoft Teams, Zoom, and WebRTC browsers. Infected devices contact a hardcoded list of 13 STUN servers; one of them, confirmed operator-controlled at 145.249.115[.]184, receives bot registrations containing infection metadata and reachability info. - Commands appear to originate from an IP belonging to Google's stun.l[.]google[.]com service. Nozomi's analysis points to source-address spoofing through a network provider that does not validate source addresses. TTL differences between genuine STUN replies and command-bearing packets are one of the few network-level tells that something is wrong. - Observed commands included internet-wide scanning for additional vulnerable targets, TCP tunneling, proxying, and UDP/TCP flood attacks. Confirmed DDoS targets included a South Korean 🇰🇷 ISP, a University of Chicago cluster, and two Minecraft servers. - Host artifacts are concrete and huntable: malware copies named .cling, persistence entries written to init scripts, and a replaced wget binary with companion files named wget.r and wget.p. Because most compromised devices offer no EDR telemetry, these filesystem indicators and network-layer patterns are often the only evidence available. Detection priority: at the network layer, hunt for STUN Binding Requests sent at short, regular intervals with transaction IDs set to all zeros, and for non-STUN UDP datagrams directed at known STUN endpoints. At the host layer, scan internet-facing embedded devices for files named .cling, modified init scripts, and replaced wget binaries. Reputation alone cannot be trusted here as packets sourced from high-reputation infrastructure are exactly what the operator is manufacturing. The full IOC list and ATT&CK mapping are in the Nozomi Networks Labs report. #DFIR_Radar

    20032399
    2.0K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    監視用DVRの脆弱性を突くボットネット攻撃が拡大し、Mirai系マルウェア「Nexcorium」による大規模DDoS基盤が構築されている。 Fortinetの分析によると、攻撃者はTBK製DVRの欠陥CVE-2024-3721を悪用し、認証不要でコマンドを実行して感染させる。 対象はDVR-4104やDVR-4216で、古いファームウェアと初期認証情報の弱さが狙われている。侵入後はMirai派生のNexcoriumが展開され、XOR設定やウォッチドッグ機構により持続性を確保しつつ、C2通信で遠隔操作される。 さらにTP-Link製ルーターの既知脆弱性CVE-2017-17215も併用し、感染範囲を拡大している。マルウェアは複数CPUに対応し、Telnetブルートフォースで自己拡散も行うため、IoT機器全体を巻き込む大規模ボットネットが形成される。これにより各機器がDDoS攻撃の踏み台となり、正規トラフィックに見える通信で検知が困難になる。 対策としては該当機器の交換、強固な認証設定、外部公開の遮断、ネットワーク分離が求められる。 https://cybersecuritynews.com/hackers-use-cve-2024-3721-to-infect-tbk-dvrs/

    Post summary

    The article reports active exploitation of CVE‑2024‑3721 in TBK DVRs by Mirai‑derived Nexcorium botnet, with further spread via TP‑Link CVE‑2017‑17215, and prescribes replacement and stronger authentication as mitigations.

    010311.4K
    14.4K followersView on X
  • Threat Landscape@LandscapeThreat

    Cling is turning STUN into an IoT botnet command-and-control channel. A report says the malware exploits CVE-2021-35394, with additional command-injection flaws targeting exposed routers, DVRs and other devices: CVE-2016-20016, CVE-2023-41011, CVE-2016-10372, CVE-2025-34037, CVE-2024-3721, CVE-2023-26801 and CVE-2014-8361. It persists through init scripts and replaces wget with a malware wrapper. Bots send periodic STUN Binding Requests with zeroed transaction IDs, followed by custom registration datagrams containing mapped ports and an infection-method tag. Researchers confirmed 145[.]249[.]115[.]184 received registrations and returned commands to an advertised port. STUN transaction ID fields encode scanning and exploitation, payload execution, TCP tunneling, proxying and DDoS commands. Some packets appeared to originate from an IP associated with Google STUN, with source-IP spoofing considered most likely. Flood instructions observed during monitoring targeted a South Korean ISP, the University of Chicago cluster and two Minecraft-related targets. Target metadata lists academia, the Republic of Korea and the United States. No actor attribution was provided. Detection artifacts include repeated zero-ID STUN requests, non-STUN datagrams sent to STUN endpoints, .cling files, init-script entries and replaced wget binaries. IOCs: hxxp://118[.]45[.]196[.]225:800/mipsel, hxxp://58[.]211[.]144[.]243:800/mipsel, hxxp://120[.]193[.]219[.]210:800/mipsel #Malware

    0103065
    106 followersView on X
  • FortiGuard Labs@FortiGuardLabs
    Active Exploitation

    IoT devices are once again in the crosshairs. ‼️ Our recent research tracks #Nexcorium, a Mirai variant exploiting vulnerable TBK DVRs to gain persistence and launch large-scale DDoS attacks. 🔎 CVE-2024-3721 exploited for initial access 📨 Multi-architecture malware for broader reach 🔓 Persistent access with brute-force and known exploits 🚨 Built for coordinated, high-impact DDoS campaigns Read our full analysis: https://ftnt.net/6018B6hmFp

    Post summary

    Research highlights that the Mirai variant #Nexcorium actively exploits CVE‑2024‑3721 on TBK DVRs to establish persistence and conduct large‑scale DDoS campaigns.

    00040330
    40.7K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet https://thehackernews.com/2026/04/mirai-variant-nexcorium-exploits-cve.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    Mirai Variant Nexcorium is actively exploiting CVE‑2024‑3721 to hijack TBK DVRs for a DDoS botnet, with no PoC, actionable patch, or technical details provided.

    01020652
    194.5K followersView on X
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting TBK DVR devices (CVE-2024-3721) 2026-08-01 19:54:28 UTC Source IP: 216.106.176.173 🇺🇸 IOCs: hxxp://95.155.151.113/d/xd.arm7 hxxp://95.155.151.113/d/xd.arm 95.155.151.113 🇳🇱 7950b0362b06908c1ee4c058bf1a95c0 b1c1836c3a1b79919267dab2278e17f4 https://t.co/ghfrI5Ruba

    Post summary

    The post reports an ongoing remote‐code‑execution attempt against TBK DVR devices identified by CVE‑2024‑3721, providing IOC URLs that likely host exploit payloads, with no patch or workaround information mentioned.

    02000273
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-33308 2 - CVE-2022-42475 3 - CVE-2026-32201 4 - CVE-2026-33827 5 - CVE-2024-3721 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A brief list of five CVE identifiers is presented without additional context or technical detail.

    00020264
    1.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows Nexcorium botnet exploiting CVE-2024-3721 in TBK DVR devices to deploy Mirai variants across networks. Attackers escalated privileges then moved laterally using additional exploits, integrating compromised devices into DDoS infrastructure. #ZeroDay 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/mirai-variant-nexcorium-exploits-cve-2024-3721-to-hijack-tbk-dvrs-for-ddos-botnet

    Post summary

    The analysis confirms that the Nexcorium botnet is actively exploiting CVE‑2024‑3721 on TBK DVR devices to deploy Mirai variants and expand a DDoS botnet.

    10010263
    1.9K followersView on X
  • Threat Landscape@LandscapeThreat

    Cling, an IoT botnet, is exploiting exposed networking gear and hiding commands inside manipulated Google STUN traffic, per Nozomi Networks. The botnet abuses CVE-2021-35394 in the Realtek Jungle SDK diagnostic component, with propagation code also carrying exploits for flaws across multiple router and DVR vendors. Persistence is maintained through copies in `/root/.cling` and `/usr/local/bin/.cling`, modified init files, and a replaced `wget` binary that forwards arguments to the original utility. Infected devices send STUN Binding Requests with all-zero transaction IDs, embedding commands in the 12-byte transaction ID field to trigger payload execution, scanning, tunneling, proxy relaying, or DDoS flooding. Nozomi flagged 145[.]249[.]115[.]184 as operator-controlled or collaborating infrastructure. Command packets appeared to originate from a Google STUN address, though source-address spoofing is considered most likely. The researchers did not establish a Google compromise, noting that contact with listed STUN servers alone does not prove malicious ownership. During monitoring, operators issued propagation and flooding instructions targeting a South Korean ISP, a University of Chicago cluster, and two Minecraft servers. These instructions were observed, but service disruptions were not independently confirmed. Vulnerabilities leveraged include CVE-2016-20016, CVE-2023-41011, CVE-2016-10372, CVE-2025-34037, CVE-2024-3721, CVE-2023-26801, CVE-2014-8361, and CVE-2021-35394. #ThreatIntel

    0001040
    112 followersView on X
  • DFIR Radar@DFIR_Radar

    Cling botnet exploits CVE-2021-35394 (CVSS 9.8) in Realtek Jungle SDK, abusing public STUN infrastructure to disguise C2 traffic as legitimate NAT-traversal activity across routers, DVRs, and embedded Linux devices. Key details: - Exploitation of CVE-2021-35394 spiked around September 5, 2026, delivering Cling (also tracked as ClingSTUN by Fortinet). The botnet embeds hard-coded exploits for seven CVEs used in self-propagation: CVE-2014-8361 (Realtek), CVE-2016-20016 (MVPower), CVE-2023-26801 (LB-LINK), CVE-2023-41011 (China 🇨🇳 Mobile/FiberHome), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), and CVE-2026-87827 (KGUARD DVR). Initial access spans a much wider set including D-Link, Tenda, Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887), TP-Link CVE-2023-1389, AVTECH CVE-2024-7029, and others. - The C2 mechanism is the standout: Cling sends STUN Binding Requests to 13 hard-coded servers every five seconds, using an all-zero transaction ID (a deliberate protocol deviation). It then sends custom UDP registration datagrams containing mapped ports and infection-source tags like realtek.selfrep or selfrep.router. Operator commands arrive embedded in the STUN transaction ID field. The controlled server 145.249.115[.]184 returns all-zero transaction IDs rather than echoing the request, the tell that it is operator-controlled. More striking: observed command packets originate from 74.125.250[.]129, an IP resolving to stun.l[.]google[.]com, making malicious replies visually indistinguishable from Google STUN responses. - Persistence is layered: the binary copies itself to /root/.cling and /usr/local/bin/.cling, then appends both paths to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot for SysV and BusyBox init survival. A secondary persistence method replaces the legitimate wget binary with the malware, relocating the original, so any legitimate process invoking wget executes the bot instead. Single-instance enforcement uses SO_REUSEADDR on port 33957. - Once established, Cling supports recursive scanning and worm-like spread, TCP tunnel spawn/stop, proxy launch/stop, and timed DoS floods. Observed flood targets include 112.151.157[.]222:8080, 192.170.240[.]137:53, and Minecraft servers at 23.81.40[.]193:25565 and 147.185.221[.]129:25565. Payloads are fetched via shell script downloaders for ARM, MIPS R3000, PowerPC, Intel 80386, and AMD X86-64, maximizing the range of vulnerable embedded hardware. Network defenders: hunt outbound UDP to port 3478 with zero-byte transaction IDs and flag UDP datagrams to public STUN servers that do not conform to RFC 5389 (non-random transaction IDs, oversized or non-standard payloads). On the host side, check for /root/.cling, /usr/local/bin/.cling, and modifications to /etc/inittab or rcS. Validate the wget binary hash against a known-good baseline: a replaced wget is a clean persistence indicator with no legitimate use case. Port 33957 bound with SO_REUSEADDR on a router or DVR is a direct Cling presence signal. Full IOC list is in the Nozomi Networks report. #DFIR_Radar

    10000204
    2.0K followersView on X

Explore more