[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:realtek-jungle-sdk-exploit-attempts-deliver-cling-botnet-with-stun-based-c2-muwikbtq":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"022ec2b3-baf1-4a67-b537-da248aac7beb","Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2","realtek-jungle-sdk-exploit-attempts-deliver-cling-botnet-with-stun-based-c2-muwikbtq","Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persistence and can pivot to exploit additional router\u002FDVR vulnerabilities, making it a serious risk for network compromise.","critical","advisory",[12],"CVE-2021-35394",[14,15,16],"Realtek Jungle SDK","Realtek","Nozomi Networks","Immediately scan your network for exploitation attempts targeting CVE-2021-35394 and for STUN protocol anomalies on ports 3478-3479. Patch or isolate any Realtek-based routers and DVRs to the latest firmware version.",[19],"3c969e11-ad7a-449e-b4e7-59e0d416f9f5",null,[22],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Frealtek-jungle-sdk-exploit-attempts.html","active","2026-10-08T10:06:16.583+00:00","2026-10-06T10:06:19.621349+00:00","2026-10-06T10:06:23.709052+00:00",[28],{"id":19,"title":6,"url":22}]