cbcvebase.
CVE-2016-5681
published 2016-08-25

CVE-2016-5681: Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before…

PriorityP182critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
11.93%
95.7th percentile
Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx before 2.05b03beta03, DIR-822 C1 3.01 before 3.01WWb02, DIR-823 A1 1.00 before 1.00WWb05, DIR-895L A1 1.11 before 1.11WWb04, DIR-890L A1 1.09 before 1.09b14, DIR-885L A1 1.11 before 1.11WWb07, DIR-880L A1 1.07 before 1.07WWb08, DIR-868L B1 2.03 before 2.03WWb01, and DIR-868L C1 3.00 before 3.00WWb01 devices allows remote attackers to execute arbitrary code via a long session cookie.

Affected

11 ranges
VendorProductVersion rangeFixed in
d-linkdir-817l_firmware<= jul.2016
d-linkdir-818l_firmware<= 2.05
d-linkdir-823_firmware<= 1.00
d-linkdir-850l_firmare<= 2.07
d-linkdir-880l_firmware<= 1.07
d-linkdir-885l_firmware<= 1.11
d-linkdir-890l_firmware<= 1.09
d-linkdir-895l_firmware<= 1.11
dlinkdir-822_firmware
dlinkdir-868l_firmware<= 2.03
dlinkdir-868l_firmware<= 3.00

Detection & IOCsextracted from sources · hover to see the quote

port2332
path/tmp/bin
processsyswapd0h
processsyswapd0w
cookielong session cookie (stack-based buffer overflow via dws/api/Login)
urldws/api/Login
  • Monitor for outbound HTTP/HTTPS connections with Protobuf-encoded, XOR-obfuscated traffic (Go build additionally uses gzip) to C2 infrastructure including ajb8.com and related hosts.
  • Detect Dropbear SSH listener on non-standard port 2332 on router devices as a persistence indicator for AryStinger.
  • Hunt for unexpected binaries dropped in /tmp/bin on affected D-Link and RTL819X-based router devices.
  • Alert on processes named syswapd0h or syswapd0w running on router or NAS devices as indicators of AryStinger infection.
  • The AryStinger router build is a Linux ELF binary targeting RTL819X (Realtek) chipset devices; flag unrecognized Linux ELF binaries appearing on such hardware.
  • Detect use of open-source recon tools fscan, ksubdomain, and httpx on NAS devices as indicators of AryStinger NAS variant activity.
  • Monitor for gs-netcat processes on NAS devices as a persistence mechanism used by the AryStinger Go-based NAS variant.
  • ·The 4,300 infection count covers only RTL819X router infections; the NAS variant infection count has not been measured by XLab.
  • ·The hardcoded key 'sh_#@!_2024_secret' may suggest a 2024 campaign start date, but XLab cannot confirm this attribution.
  • ·AryStinger has not been attributed to any known threat actor; attribution remains unresolved.
  • ·The router C build is limited to mass DNS scanning and traffic tunneling due to hardware constraints of old RTL819X chips; the more capable NAS Go build targets QNAP devices via a separate CVE (CVE-2025-11837).

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.