CVE-2025-11837
Malware Remover
Description
An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attackers can then exploit the vulnerability to bypass protection mechanism. We have already fixed the vulnerability in the following version: Malware Remover 6.6.8.20251023 and later
In plain language
AI Act nowCVE-2025-11837 is a serious remote code execution flaw in Malware Remover that attackers are actively exploiting in the wild; if you use Malware Remover and are not on the fixed version, you should act immediately.
CVE-2025-11837 is a remotely exploitable code-generation/control weakness (CWE-94) in Malware Remover that allows unauthenticated attackers to execute arbitrary code or bypass protections; exploitation is confirmed in the wild via the AryStinger campaign targeting legacy routers.
What to do now
- Check your installed Malware Remover version and confirm whether it is earlier than 6.6.8.20251023.
- If you are on an earlier version, upgrade Malware Remover to 6.6.8.20251023 or later.
- If you cannot upgrade right away, isolate the affected system from the internet and any untrusted networks until the upgrade is completed.
- After upgrading, verify the Malware Remover service is running normally and re-check the installed version to ensure the update actually took effect.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- AryStinger Malware Attacks Routers via CVE-2013-3307en-us·Daily CyberSecurity (securityonline.info)· Research RTL819X routers ics-ot-iot
- Ботнет AryStinger заразил тысячи роутеров D-Linkru-ru·Хакер (xakep.ru)· Exploited D-Link DIR-850L AryStinger
- AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Networken·The Hacker News· Exploited Linksys routers (RTL819X-based models) malware
- AryStinger botnet infected thousands of D-Link routers worldwideen-us·BleepingComputer· Research AryStinger malware
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-11837 and every CVE in our database. Create a free account — no credit card required.
Create Free Account