Vulnerabilities & Exploits

Cling Uses STUN Traffic to Hide Router Exploits

Nozomi Networks said exploitation attempts against Realtek Jungle SDK CVE-2021-35394 spiked around September 5, 2026, and some of the attacks dropped Cling botnet malware. The flaw is a critical remote code execution bug in devices built on the SDK, including router and DVR fleets.

Cling turns public STUN (Session Traversal Utilities for NAT) infrastructure into its command channel. It sends binding requests to public STUN servers and receives replies that look like ordinary NAT-traversal traffic, which lets the botnet register hosts and receive commands while blending into traffic defenders may not want to block.

For operators that rely on STUN for WebRTC, voice, or other NAT-traversal services, the exposure is not just a patched device but a harder-to-see control path inside traffic that can look normal. If those flows are common in your network, containment now has to account for both the device compromise and the camouflage layer it uses.

3 sources · 3h ago

CVE-2021-35394

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. EPSS 100% (100th percentile).

CISA federal remediation date Dec 24 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-10-05

Every edition of this story: Cling Uses STUN Traffic to Hide Router Exploits

More from today