Skip to content
Cling Botnet Exploits Realtek Jungle SDK Vulnerability

Cling Botnet Exploits Realtek Jungle SDK Vulnerability

First seen 5 Oct 2026, 14:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 14:26 UTC
  • •CVE-2021-35394 is a critical RCE vulnerability in Realtek Jungle SDK.
  • •Cling botnet exploits STUN traffic for covert command-and-control operations.
  • •Active exploitation attempts began in early September 2026, despite the patch being available.

Threat actors are exploiting a critical vulnerability (CVE-2021-35394) in the Realtek Jungle SDK to deploy a botnet malware named Cling. This malware utilizes STUN traffic to create a covert command-and-control channel, allowing it to blend in with legitimate network activity. The vulnerability, which has a CVSS score of 9.8, affects versions v2.x to v3.4.14B of the SDK, widely used in IoT devices and routers. Exploitation attempts began around September 5, 2026, with the malware embedding exploit logic for multiple other vulnerabilities in routers and DVRs. The Cling botnet can achieve persistence on infected systems by modifying system files and replacing legitimate binaries. As of October 5, 2026, the vulnerability has been patched, but attempts have been observed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2015-05-01
CVE-2014-8361 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-05-16
CVE-2016-10372 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-08-16
CVE-2021-35394 published
A critical vulnerability affecting Realtek Jungle SDK versions v2.x to v3.4.14B was disclosed.
www.sentinelone.com
2022-10-19
CVE-2016-20016 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-03-26
CVE-2023-26801 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-09-14
CVE-2023-41011 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-04-13
CVE-2024-3721 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-24
CVE-2025-34037 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-05
Exploitation attempts observed
Threat actors began exploiting CVE-2021-35394 to deploy the Cling botnet, utilizing STUN traffic.
Thehackernews
2026-10-05
Cling botnet activity reported
Nozomi Networks reported on the Cling botnet's operational techniques and the ongoing exploitation attempts.
Thehackernews

More articles in this cluster (6)

Following this threat?

Track Cling and CVE-2014-8361 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which devices are affected by CVE-2021-35394?
The vulnerability affects Realtek Jungle SDK versions v2.x to v3.4.14B, commonly used in IoT devices and routers.
Is the vulnerability still being exploited?
Yes, active exploitation attempts have been reported as of early September 2026.
What actions should be taken to mitigate this risk?
Ensure that the latest patches for the Realtek Jungle SDK are applied to affected devices.