CVE-2025-11837Active Exploitation(qnap / malware_remover)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch qnap malware_remover systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • malware_remover

Threat summary

  • Active exploitation appears in 7 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-06-21); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
malware_remover

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-03-17: 1Mentions · 2026-06-18: 1Mentions · 2026-06-21: 3Mentions · 2026-06-22: 3Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-07-13: 1Exploit Tool / Code · 2026-06-22: 1Exploit Tool / Code · 2026-07-13: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-21: 3Active Exploitation · 2026-06-22: 3Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-22: 2Technical Details · 2026-03-17: 1Technical Details · 2026-06-22: 1Technical Details · 2026-07-13: 103-1706-1806-2106-2207-13
Signal classification3 categories
Active Exploitation
777.8%
Disclosure
111.1%
PoC
111.1%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-171
Disclosure1
2026-06-181
Active Exploitation1
2026-06-213
Active Exploitation3
2026-06-223
Active Exploitation3
2026-07-131
PoC1
Full discourse9 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-198|CVE-2025-11837] (Pwn2Own) QNAP TS-453E malware_remover Code Injection Remote Code Execution Vulnerability (CVSS 8.8; Credit: Chumy Tsai (http://github.com/Jimmy01240397) @ CyCraft Technology Intern) https://www.zerodayinitiative.com/advisories/ZDI-26-198/

    Post summary

    An advisory on Zeroday Initiative announces a code injection remote‑code‑execution vulnerability (CVE‑2025‑11837) in QNAP TS‑453E with a CVSS score of 8.8, directing readers to the full advisory for details.

    000631.0K
    5.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    الاستهداف مركز على راوترات D-Link القديمة: 📍 DIR-850L 📍 DIR-818LW ويستغل ثغرات مثل: 📍 CVE-2013-3307 📍 CVE-2016-5681 📍 CVE-2025-11837

    Post summary

    The post claims that old D-Link routers are being actively targeted and exploited using CVE‑2013‑3307, CVE‑2016‑5681, and CVE‑2025‑11837, but offers no detailed technical or mitigation information.

    100501.3K
    50.1K followersView on X
  • Morty@MortyJin
    PoC

    CVE-2025-11837: an unauthenticated Python code injection in QNAP Malware Remover, traced from one new isalnum in the patch to full root RCE via a cookie-spliced python -c template. https://rustlang.rs/posts/blog_cve_2025_11837_en/

    Post summary

    The post details a PoC for CVE-2025-11837—a Python code injection in QNAP Malware Remover that achieves full root RCE using a cookie‑spliced python -c template, and links to a blog post for further information.

    0002097
    164 followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    AryStinger a new botnet has turned 4,000+ end-of-life D-Link routers (DIR-850L, DIR-818LW) into distributed attack proxies. Exploits: CVE-2013-3307, CVE-2016-5681, CVE-2025-11837. Infected devices scan, proxy, tunnel, hijack DNS, and sniff all traffic. A second Go variant targets NAS, running Shell/Go/Java/Python payloads. 48% of infections sit in South Korea. No attribution to any known cluster. The hardware is EoL no patch is coming. Replace it and kill remote management. Source: @BleepinComputer @VulnerabilityNw

    Post summary

    A botnet is actively exploiting three known CVEs on end‑of‑life D‑Link routers, with no patch available and widespread infection, mainly in South Korea.

    0101082
    184 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    AryStinger malware turns 4,300+ end-of-life Realtek RTL819X routers into a distributed reconnaissance botnet, exploiting CVEs from 2013 and 2016 with zero VirusTotal detections at discovery. - Initial access via CVE-2013-3307 and CVE-2016-5681, both over a decade old, spreading a C-based ELF binary from 107.150.106[.]45. The C build persists by dropping Dropbear SSH on port 2332 and communicates via HTTP with Protobuf traffic XOR-encrypted using the hardcoded key sh_#@!_2024_secret, suggesting the op predates the March 12, 2026 detection. - A Go-based second build targets QNAP NAS devices via CVE-2025-11837, patched November 2025 and exploited within five months. It integrates fscan, ksubdomain, httpx, and Tlsx, plus a ScriptWork engine that executes attacker-supplied Go, Java, or Python source directly on device, dropping plaintext payloads to disk. - The fleet operates as an ORB network: each Executor node receives a scan slice, runs it in parallel, and returns results, masking true operator origin. D-Link DIR-850L accounts for ~75% of infected devices. - C2 and download infrastructure uses ajb8[.]com, dataexplore[.]cc, and dataexplore[.]co. Watch for processes named syswapd0h or syswapd0w and unexpected binaries in /tmp/bin. Hunt outbound connections to those three domains, check /tmp/bin, and audit for Dropbear SSH on port 2332. #DFIR_Radar

    Post summary

    The report describes an active, widespread exploitation campaign against routers and NAS devices using multiple CVEs, with specific exploit methods and a patch status for one vulnerability.

    10000253
    1.7K followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 NEW: AryStinger — a previously undocumented botnet — has compromised 4,000+ D-Link routers (DIR-850L, DIR-818LW) by exploiting end-of-life vulnerabilities: CVE-2013-3307, CVE-2016-5681, CVE-2025-11837. Infected routers become distributed scanning proxies, tunnels, and command executors for follow-on intrusion operations. The genius: AryStinger splits massive scanning tasks into parallel chunks across compromised routers, covering their tracks in the process. 48.5% of infections are in South Korea, 31.8% China, with secondary clusters in Sweden, Malaysia, Singapore. A Go-based variant also targets NAS systems. The same router models were previously hit by AVrecon. If you own a D-Link DIR-850L or DIR-818LW, assume it’s compromised. Replace it now. Full breakdown 👇 https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/

    Post summary

    The AryStinger botnet exploits end‑of‑life vulnerabilities in D‑Link routers, compromising thousands of devices and turning them into scanning proxies; users are urged to replace the hardware immediately.

    1000092
    85 followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 UPDATE — AryStinger: No new attribution yet — but the pattern is unmistakable. AryStinger hits the SAME D-Link models (DIR-850L, DIR-818LW) previously targeted by AVrecon, which Lumen disrupted in 2023. And one of the vulnerabilities AryStinger uses (CVE-2025-11837) is from 2025 — meaning it's actively hunting newly discovered flaws. The broader context: D-Link DIR-823X routers are currently being exploited by Mirai variants via CVE-2025-29635, a flaw that went unexploited for a full year. D-Link DSL models are under attack from multiple gangs exploiting CVE-2026-0625. This isn't one botnet targeting one model — it's a coordinated ecosystem. End-of-life D-Link routers are the new botnet commons. Replace yours now. 👇 https://www.bleepingcomputer.com/news/security/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/

    Post summary

    The post reports that AryStinger is exploiting CVE‑2025‑11837 on D‑Link routers, while other CVEs (CVE‑2025‑29635 and CVE‑2026‑0625) are actively exploited by Mirai variants and gangs, highlighting a coordinated botnet targeting end‑of‑life devices.

    0000070
    85 followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    AryStinger botnet has compromised 4,000+ EoL D-Link routers, converting them into distributed scanning and proxy infrastructure for malicious traffic. The malware also hijacks DNS and can intercept all network traffic. CVE-2025-11837 is among the exploited flaws.

    Post summary

    The botnet AryStinger is actively exploiting CVE-2025-11837 on more than 4,000 end‑of‑life D-Link routers, repurposing them for malicious traffic.

    0000099
    577 followersView on X
  • Meridian Group@MeridianEU
    Active Exploitation

    #AryStinger botnet compromised 4,000+ legacy D-Link routers and NAS devices via CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837. Infected devices used as proxy infrastructure to mask secondary malicious activity. Opportunistic targeting focused on end-of-life hardware. https://t.co/umW9gf0hzS

    Post summary

    The AryStinger botnet is actively exploiting multiple legacy D-Link devices in the wild via CVE‑2013‑3307, CVE‑2016‑5681, and CVE‑2025‑11837, using them as proxy infrastructure for further malicious activity.

    00000130
    60 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqnapmalware_remover---

Explore more