Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

A newly discovered exploit targeting the Realtek Jungle SDK, a widely used software development kit (SDK) for IoT devices and routers, has uncovered a sophisticated botnet dubbed “Cling.” The botnet uses STUN-based command-and-control (C2) communications to evade detection and wreak havoc on compromised networks.

The Cling botnet is notable for its ability to spread across domains and exploit vulnerabilities in Realtek’s Jungle SDK, which provides a range of functionalities for IoT devices, including Wi-Fi management and network access control. The exploit takes advantage of a privilege escalation vulnerability, allowing attackers to gain unauthorized access to sensitive areas of the device’s system.

Researchers have identified over 150,000 compromised devices, with the majority located in Asia and Europe. This botnet has significant implications for individuals and organizations that rely on IoT devices for critical operations or personal data security. The Cling botnet’s use of STUN-based C2 communications allows it to maintain a covert presence within networks, making detection and remediation challenging.

The discovery highlights the importance of keeping software development kits (SDKs) and other dependencies up-to-date, as outdated versions can leave systems vulnerable to exploitation. This is particularly concerning for IoT devices, which are often connected to critical infrastructure or sensitive data and are frequently overlooked in security patching cycles.

Realtek has acknowledged the vulnerability and released a patch to address the issue. However, the widespread adoption of the affected SDKs suggests that many organizations may be unaware of the potential risks. As IoT devices continue to play an increasingly prominent role in modern life, it is essential for individuals and businesses to prioritize security measures, including regular software updates and thorough vulnerability assessments.

In light of this discovery, we recommend that users take proactive steps to ensure their IoT devices are secure. This includes keeping all connected devices and their associated SDKs updated with the latest patches, implementing robust network segmentation, and conducting regular vulnerability scans to identify potential entry points for attackers.


Source: The Hacker News — 2026-10-05