CVE-2016-5681
published 2016-08-25CVE-2016-5681: Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before…
PriorityP182critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
11.93%
95.7th percentile
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-817l_firmware | <= jul.2016 | — |
| d-link | dir-818l_firmware | <= 2.05 | — |
| d-link | dir-823_firmware | <= 1.00 | — |
| d-link | dir-850l_firmare | <= 2.07 | — |
| d-link | dir-880l_firmware | <= 1.07 | — |
| d-link | dir-885l_firmware | <= 1.11 | — |
| d-link | dir-890l_firmware | <= 1.09 | — |
| d-link | dir-895l_firmware | <= 1.11 | — |
| dlink | dir-822_firmware | — | — |
| dlink | dir-868l_firmware | <= 2.03 | — |
| dlink | dir-868l_firmware | <= 3.00 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for outbound HTTP/HTTPS connections with Protobuf-encoded, XOR-obfuscated traffic (Go build additionally uses gzip) to C2 infrastructure including ajb8.com and related hosts. ↗
- →Detect Dropbear SSH listener on non-standard port 2332 on router devices as a persistence indicator for AryStinger. ↗
- →Hunt for unexpected binaries dropped in /tmp/bin on affected D-Link and RTL819X-based router devices. ↗
- →Alert on processes named syswapd0h or syswapd0w running on router or NAS devices as indicators of AryStinger infection. ↗
- →The AryStinger router build is a Linux ELF binary targeting RTL819X (Realtek) chipset devices; flag unrecognized Linux ELF binaries appearing on such hardware. ↗
- →Detect use of open-source recon tools fscan, ksubdomain, and httpx on NAS devices as indicators of AryStinger NAS variant activity. ↗
- →Monitor for gs-netcat processes on NAS devices as a persistence mechanism used by the AryStinger Go-based NAS variant. ↗
- ·The 4,300 infection count covers only RTL819X router infections; the NAS variant infection count has not been measured by XLab. ↗
- ·The hardcoded key 'sh_#@!_2024_secret' may suggest a 2024 campaign start date, but XLab cannot confirm this attribution. ↗
- ·AryStinger has not been attributed to any known threat actor; attribution remains unresolved. ↗
- ·The router C build is limited to mass DNS scanning and traffic tunneling due to hardware constraints of old RTL819X chips; the more capable NAS Go build targets QNAP devices via a separate CVE (CVE-2025-11837). ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x7m8-97xv-fx44: Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2
ghsa_unreviewed·2022-05-17
CVE-2016-5681 [CRITICAL] CWE-119 GHSA-x7m8-97xv-fx44: Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.
VulnCheck
D-Link dir-868l_firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2016·CVSS 9.8
CVE-2016-5681 [CRITICAL] D-Link dir-868l_firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
D-Link dir-868l_firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.
Affected: D-Link dir-868l_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploit
No detection rules found.
No public exploits indexed.
Hackernews
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
blogs_hackernews·2026-06-22·CVSS 8.3
CVE-2013-3307 [HIGH] AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is still rising.
The distinction matters. AryStinger exists for the stage of an attack that comes before the break-in. Infected devices scan the internet, fingerprint services, enumerate subdomains, tunnel traffic, and run commands on demand, then ship the results back to the operator.
Ea
Bleepingcomputer
AryStinger botnet infected thousands of D-Link routers worldwide
blogs_bleepingcomputer·2026-06-21·CVSS 8.3
CVE-2013-3307 [HIGH] AryStinger botnet infected thousands of D-Link routers worldwide
## AryStinger botnet infected thousands of D-Link routers worldwide
## Bill Toulas
A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic.
Researchers at Qianxin's XLab threat intelligence team say that the malware converts infected devices into remotely controlled “executors” that can perform scanning, proxying, tunneling, command execution, and other activities on behalf of the attacker.
“The attacker can split a massive scanning task into multiple small chunks and distribute them to different Executors for parallel execution,” XLab researchers note .
“With this distributed-like design, the attacker can efficiently complete the early "footprinting" activities, thereby providing strong
http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10063http://www.kb.cert.org/vuls/id/332115http://www.securityfocus.com/bid/92427http://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10063http://www.kb.cert.org/vuls/id/332115http://www.securityfocus.com/bid/92427
2016-08-25
Published
Exploited in the wild