MalwareBleeping Computer
9.8 — CRITICAL
AryStinger botnet infected thousands of D-Link routers worldwide
A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
AryStinger botnet infected thousands of D-Link routers worldwide, compromising them as proxies for malicious traffic and allowing attackers to scan, proxy, tunnel, and execute commands on behalf of the attacker.
⚙️Technical Details
CVEs
CVE-2013-3307CVE-2016-5681CVE-2025-11837Affected Systems: D-Link DIR-850L, D-Link DIR-818LW routersAttack Vectors: NETWORK
Affected Systems
D-Link DIR-850L, D-Link DIR-818LW routers
Attack Vectors
NETWORK
💥Impact Assessment
Severity: critical
🛡️Recommended Actions
1Owners should replace them with new, actively supported models
2Apply the latest available firmware updates
3Change the default administrator account password and disable remote management panels
📦Affected Products
D-Link Dir-817L\(W\) FirmwareD-Link Dir-818L\(W\) FirmwareD-Link Dir-823 FirmwareD-Link Dir-850L FirmareD-Link Dir-880L FirmwareD-Link Dir-885L FirmwareD-Link Dir-890L FirmwareD-Link Dir-895L FirmwareDlink Dir-817L\(W\)Dlink Dir-818L\(W\)
🔐NVD Verified DataVERIFIED
CVE-2016-5681 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-119
Affected Products (CPE)
D-Link Dir-817L\(W\) FirmwareD-Link Dir-818L\(W\) FirmwareD-Link Dir-823 FirmwareD-Link Dir-850L FirmareD-Link Dir-880L Firmware
CVE-2025-11837 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-94
Affected Products (CPE)
Qnap Malware Remover
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
