CVE-2013-3307
CVSS 8.3 HIGH: linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command… EPSS 56% (99th percentile).
Vulnerabilities & Exploits · IoT / OT Attack
The danger is not just that thousands of home routers are infected. They are being used as a distributed layer for scanning, proxying, and traffic relay, which makes attacker reconnaissance look like ordinary residential traffic and makes IP blocking far less effective. Compromised routers can also change DNS settings, so the attacker can redirect browsing without touching passwords.
Qianxin XLab says AryStinger is active on more than 4,000 outdated D-Link routers, with most infections tied to DIR-850L and DIR-818LW devices. The malware turns each device into a remote executor for scanning and proxy work, and it can also tamper with DNS and inspect network traffic. The group uses older flaws, including CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837.
The forward risk is persistence at scale: once routers are in this state, they become a reusable residential proxy and reconnaissance fabric for later intrusions. That changes both attribution and containment, because the attacker is no longer coming from one source address.
2 sources · Jun 22
CVSS 8.3 HIGH: linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command… EPSS 56% (99th percentile).
CVSS 9.8 CRITICAL: stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx… EPSS 12% (96th percentile).
CVSS 9.8 CRITICAL: an improper control of generation of code vulnerability has been reported to affect Malware Remover. EPSS 1% (72nd percentile).
The Hacker News
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
AryStinger malware has infected 4,300 Realtek RTL819X routers, using old CVEs to scan targets, tunnel traffic, and hide attacker activity.
originalBleepingComputer
AryStinger botnet infected thousands of D-Link routers worldwide
A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.
originalPart of the PlainSec briefing for 2026-06-22
Every edition of this story: Infected Routers Become a Hidden Scanning Fabric