Skip to content
October 11, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • VPNFilter malware performs an active man-in-the-middle attack with capable downgrade HTTPS
  • Malware

VPNFilter malware performs an active man-in-the-middle attack with capable downgrade HTTPS

Do Son June 7, 2018 2 minutes read
VPNFilter malware
Add Daily CyberSecurity as a preferred source on Google

After further analysis, the Cisco security researchers found that the malicious program VPNFilter was more powerful and destructive than earlier thought. Hackers working for the Russian government used VPNFilter to infect 500,000 routers worldwide. The infected router brands include Linksys, MikroTik, Netgear, and TP-Link.

Now researchers report that the routers of Asus, Huawei, ZTE, and D-Link are also infected. Cisco researchers discovered a man-in-the-middle attack module, ssler, from the VPNFilter that allows attackers to inject malicious traffic into the traffic passing through the compromised router. It can even quietly modify what the site sends. Ssler is also designed to steal sensitive data such as passwords. Such data is usually an encrypted transmission and the ssler will attempt to downgrade an HTTPS connection to a clear text HTTP connection.

Ssler also adjusted traffic for Google, Facebook, Twitter, and Youtube specifically because these sites provide additional security features, such as Google automatically redirecting HTTP traffic to HTTPS. Ssler also removes the data compression provided by gzip because plaintext traffic is easier to modify.

The full list of targeted devices is:

ASUS DEVICES:

RT-AC66U (new)
RT-N10 (new)
RT-N10E (new)
RT-N10U (new)
RT-N56U (new)
RT-N66U (new)

D-LINK DEVICES:

DES-1210-08P (new)
DIR-300 (new)
DIR-300A (new)
DSR-250N (new)
DSR-500N (new)
DSR-1000 (new)
DSR-1000N (new)

HUAWEI DEVICES:

HG8245 (new)

LINKSYS DEVICES:

E1200
E2500
E3000 (new)
E3200 (new)
E4200 (new)
RV082 (new)
WRVS4400N

MIKROTIK DEVICES:

CCR1009 (new)
CCR1016
CCR1036
CCR1072
CRS109 (new)
CRS112 (new)
CRS125 (new)
RB411 (new)
RB450 (new)
RB750 (new)
RB911 (new)
RB921 (new)
RB941 (new)
RB951 (new)
RB952 (new)
RB960 (new)
RB962 (new)
RB1100 (new)
RB1200 (new)
RB2011 (new)
RB3011 (new)
RB Groove (new)
RB Omnitik (new)
STX5 (new)

NETGEAR DEVICES:

DG834 (new)
DGN1000 (new)
DGN2200
DGN3500 (new)
FVS318N (new)
MBRN3000 (new)
R6400
R7000
R8000
WNR1000
WNR2000
WNR2200 (new)
WNR4000 (new)
WNDR3700 (new)
WNDR4000 (new)
WNDR4300 (new)
WNDR4300-TN (new)
UTM50 (new)

QNAP DEVICES:

TS251
TS439 Pro
Other QNAP NAS devices running QTS software

TP-LINK DEVICES:

R600VPN
TL-WR741ND (new)
TL-WR841N (new)

UBIQUITI DEVICES:

NSM2 (new)
PBE M5 (new)

UPVEL DEVICES:

Unknown Models* (new)

ZTE DEVICES:

ZXHN H108N (new)

FBI Remind User to Restart Router to Remove VPNFILTER malware.

Related coverage

  • OneNote Exploited: Malicious Campaigns Unveiled in Note-Taking App
  • Nation-State Espionage: Airstalk Malware Hijacks VMware AirWatch (MDM) API for Covert C2 Channel
  • DOGE Big Balls Ransomware: New Tools and Tactics Uncovered
  • New Trojan “MiyaRat” Unleashed by Bitter Group (APT-Q-37)
  • The High Cost of ‘Free’: How PiviGames Became a Lovecraftian Malware Hub for HijackLoader and ACRStealer
  • KimJongRAT Returns: New PE & PowerShell Variants Steal Crypto and Browser Data via CDNs
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: VPNFilter malware

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2026-105133CVSS 6.9
    A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file...
    Admin intel📅 Updated: Oct 9, 2026
  • CVE-2023-22894CVSS 4.9
    Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2016-3081CVSS 8.1
    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled,...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-3306CVSS 10.0
    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2015-5477CVSS 7.5
    named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2021-3199CVSS 9.8
    Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
    CISA KEV📅 Added to KEV: Oct 8, 2026
  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-97670CVSS 9.1
    The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
    📅 Updated: Oct 11, 2026
  • CVE-2026-94589CVSS 9.8
    The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to...
    📅 Updated: Oct 11, 2026
  • CVE-2026-107645CVSS 9.1
    The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58...
    📅 Updated: Oct 11, 2026
  • CVE-2026-104803CVSS 9.8
    The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
    📅 Updated: Oct 11, 2026
  • CVE-2026-104801CVSS 9.1
    The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file...
    📅 Updated: Oct 11, 2026
  • CVE-2026-104732CVSS 9.8
    The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and...
    📅 Updated: Oct 11, 2026
  • CVE-2026-103889CVSS 9.8
    The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions...
    📅 Updated: Oct 11, 2026
  • CVE-2026-102628CVSS 9.2
    The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible...
    📅 Updated: Oct 11, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.