Securityweek ClingSTUN Linux Backdoor Exploits 24 IoT Vulnerabilities
Article Content
- •ClingSTUN exploits 24 known vulnerabilities in IoT devices, turning them into proxy nodes.
- •The malware uses legitimate STUN servers to obscure its communications, complicating detection.
- •FortiGuard Labs has not identified the attackers or the extent of the infections.
Researchers from FortiGuard Labs have identified a new Linux backdoor named ClingSTUN that exploits 24 known vulnerabilities in Internet of Things (IoT) devices. This malware turns infected devices into proxy nodes, using legitimate public STUN servers to obscure communications. The vulnerabilities targeted include critical flaws from manufacturers like D-Link, Realtek, and TP-Link. ClingSTUN establishes persistence on compromised systems and can propagate itself using hardcoded exploits for seven additional vulnerabilities. The malware has been observed in multiple attack waves, with its operators expanding the list of exploited vulnerabilities over time. FortiGuard Labs has not confirmed the identity of the attackers or the number of affected devices. The use of legitimate STUN servers complicates detection, as the traffic resembles normal Internet communications. Organizations are urged to inventory their IoT devices and prioritize patching to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track ClingSTUN, Realtek and CVE-2022-36553 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which devices are affected by ClingSTUN?
What should organizations do to protect against ClingSTUN?
Is there a known method for detecting ClingSTUN infections?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…