إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediActive Exploitation
The post claims that old D-Link routers are being actively targeted and exploited using CVE‑2013‑3307, CVE‑2016‑5681, and CVE‑2025‑11837, but offers no detailed technical or mitigation information.
Morty[verified]@MortyJinPoC
The post details a PoC for CVE-2025-11837—a Python code injection in QNAP Malware Remover that achieves full root RCE using a cookie‑spliced python -c template, and links to a blog post for further information.
Elusive[verified]@ElusivePrivacyActive Exploitation
A botnet is actively exploiting three known CVEs on end‑of‑life D‑Link routers, with no patch available and widespread infection, mainly in South Korea.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The report describes an active, widespread exploitation campaign against routers and NAS devices using multiple CVEs, with specific exploit methods and a patch status for one vulnerability.
CyberAlertsHQ[verified]@CyberAlertsHQActive Exploitation
The AryStinger botnet exploits end‑of‑life vulnerabilities in D‑Link routers, compromising thousands of devices and turning them into scanning proxies; users are urged to replace the hardware immediately.
CyberAlertsHQ[verified]@CyberAlertsHQActive Exploitation
The post reports that AryStinger is exploiting CVE‑2025‑11837 on D‑Link routers, while other CVEs (CVE‑2025‑29635 and CVE‑2026‑0625) are actively exploited by Mirai variants and gangs, highlighting a coordinated botnet targeting end‑of‑life devices.
Xavier Rivera[verified]@XavierRiveraXActive Exploitation
The botnet AryStinger is actively exploiting CVE-2025-11837 on more than 4,000 end‑of‑life D-Link routers, repurposing them for malicious traffic.
TheZDIBugs@TheZDIBugsDisclosure
An advisory on Zeroday Initiative announces a code injection remote‑code‑execution vulnerability (CVE‑2025‑11837) in QNAP TS‑453E with a CVSS score of 8.8, directing readers to the full advisory for details.