CVE-2013-3307
CVSS 8.3 HIGH: linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command… EPSS 56% (99º percentile).
Vulnerabilità ed exploit · Attacco IoT / OT
Il pericolo non è solo l'infezione di 4.000 router: è la trasformazione di dispositivi domestici in una struttura distribuita per scansione e relay. Così il traffico di ricognizione e le prime fasi di intrusione arrivano da molte IP residenziali, si frammentano e diventano molto più difficili da attribuire o bloccare.
Qianxin XLab attribuisce ad AryStinger il controllo di oltre 4.000 router D-Link obsoleti, soprattutto DIR-850L e DIR-818LW. Il malware li usa come executors remoti per scanning, proxying, tunneling e command execution, e può anche alterare il DNS e osservare il traffico in transito; le infezioni si concentrano soprattutto in Corea del Sud e Cina.
Per chi difende servizi esposti su Internet, il punto non è il singolo modello colpito ma la comparsa di una fascia di infrastruttura avversaria fatta di router compromessi. Una volta entrati in questa rete, gli attaccanti possono mascherare la ricognizione e rendere molto meno efficace il blocco basato sugli IP.
2 fonti · 22 giu
CVSS 8.3 HIGH: linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command… EPSS 56% (99º percentile).
CVSS 9.8 CRITICAL: stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx… EPSS 12% (96º percentile).
CVSS 9.8 CRITICAL: an improper control of generation of code vulnerability has been reported to affect Malware Remover. EPSS 2% (74º percentile).
The Hacker News
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
AryStinger malware has infected 4,300 Realtek RTL819X routers, using old CVEs to scan targets, tunnel traffic, and hide attacker activity.
originaleBleepingComputer
AryStinger botnet infected thousands of D-Link routers worldwide
A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.
originalePart of the PlainSec briefing for 2026-06-21
Every edition of this story: Migliaia di router D-Link diventano una rete di proxy e scanner