Exploited in the wild Linksys routers (RTL819X-based models) malware D-Link DIR-850L (DIR-850L largely targeted) Linksys network-edge
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
CVE Tools coverage
QiAnXin’s XLab reports that its AryStinger malware has infected at least 4,300 legacy routers and repurposes them for pre-intrusion reconnaissance and proxying (scanning, service fingerprinting, subdomain enumeration, tunneling, and on-demand command execution). The activity targets routers using Realtek RTL819X chips and exploits older, already-public issues: CVE-2013-3307 (Linksys) and CVE-2016-5681 (D-Link), with the majority of infected devices attributed to D-Link models such as DIR-850L. A separate strain was also observed against QNAP systems via CVE-2025-11837 in QNAP's Malware Remover, underscoring how unsupported networking gear can be used to build resilient attacker infrastructure.