
CVE-2013-3307, CVE-2016-5681, CVE-2025-11837: D-Link Routers — AryStinger Botnet Mass Compromise (June 2024)
CVE-2013-3307, CVE-2016-5681, CVE-2025-11837 — D-Link Routers
AryStinger botnet operators are actively exploiting CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 (high severity) to compromise over 4,000 outdated D-Link DIR-850L and DIR-818LW routers worldwide. These vulnerabilities allow remote attackers to fully control affected routers, converting them into proxies for malicious activity. Exploitation is confirmed and ongoing.
Attack Vector
Attackers scan the internet for exposed D-Link DIR-850L and DIR-818LW routers running outdated firmware. Using exploits for the listed CVEs, they gain remote code execution and deploy AryStinger malware. Infected routers are enrolled into a botnet, enabling distributed scanning, proxying, tunneling, DNS hijacking, and command execution. The botnet infrastructure can be redirected for data theft or large-scale DNS attacks. Nearly half of observed infections are in South Korea, with significant clusters in China, Sweden, Malaysia, and Singapore.
Who Is at Risk
All organizations and individuals operating D-Link DIR-850L and DIR-818LW routers with unpatched or unsupported firmware are at immediate risk. D-Link is the affected vendor. Infections are confirmed globally, with a concentration in East Asia and Northern Europe. Devices used as internet gateways or exposed to the public internet are most vulnerable.
Patch & Mitigate
- Patch: Immediately update DIR-850L and DIR-818LW routers to the latest available firmware. If no patch exists, replace the device.
- Workaround: Isolate affected routers from the internet or restrict remote management access. Disable UPnP and remote administration features.
- Detect: Monitor for unusual outbound connections, unexpected DNS queries, or proxy traffic originating from router IPs. Check for unauthorized processes or firmware modifications.
MITRE ATT&CK
- TA0005 — Defense Evasion: Attackers modify router firmware to evade detection and maintain persistence.
- TA0007 — Discovery: Compromised routers are used to scan and enumerate additional targets across the internet.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

