Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Researchers reveal Ecscape’s flaws in Amazon ECS that allow cross-task qualification theft

Upwork is buying its way to staffing companies beyond freelancers

Fake VPN and spam blocker apps associated with vextrio used in ad fraud, subscription scams

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds three D-Wind Router flaws to KEV catalog after active exploitation report
Identity

CISA adds three D-Wind Router flaws to KEV catalog after active exploitation report

userBy userAugust 6, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 6, 2025Ravi LakshmananVulnerability/Firmware Security

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three old security flaws affecting D-Link routers to its known Exploited Vulnerabilities (KEV) catalogue based on evidence of aggressive wild exploitation.

High-strength vulnerabilities from 2020 and 2022 are listed below –

CVE-2020-25078 (CVSS score: 7.5) – Unspecified vulnerability in DCS-2530L and DCS-2670L devices CVE-2020-25079 (CVSS score: 8.8) – Command injection vulnerability demonstrating vulnerability in CGI-BIN/DNS_ECNS_ENC DCS-2530L and DCS-2670L devices CVE-2020-40799 (CVSS score: 8.8) – Download code without integrity check D-Link The vulnerability in DNR-322L allows an attacker who has been authenticated to execute operating system-level commands on a device that is capable of executing operating system-level commands.

Cybersecurity

Currently, there is no details on how these shortcomings are exploited in the wild, but an advisory from the US Federal Bureau of Investigation (FBI) in December 2024 warned about the Hiatusrat campaign, which aggressively scans vulnerable webcams against CVE-2020-25078.

It is worth noting that as of November 2021, CVE-2020-40799 remains below that CVE-2020-40799 is present as the affected model has reached end-of-life (EOL) status. The fix for the other two flaws was released by D-Link in 2020.

In light of active exploitation, it is essential that federal civil enforcement sector (FCEB) agencies implement necessary mitigation procedures by August 26, 2025 to ensure their networks.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWatching crabs defeat the robot “Wave Dave” after they permeate their claw swimmer contest
Next Article AI Is Transforming Cybersecurity Adversarial Testing
user
  • Website

Related Posts

Researchers reveal Ecscape’s flaws in Amazon ECS that allow cross-task qualification theft

August 6, 2025

Fake VPN and spam blocker apps associated with vextrio used in ad fraud, subscription scams

August 6, 2025

AI slashes VCISO workloads by 68% as SMBS demands more – new report reveals

August 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Researchers reveal Ecscape’s flaws in Amazon ECS that allow cross-task qualification theft

Upwork is buying its way to staffing companies beyond freelancers

Fake VPN and spam blocker apps associated with vextrio used in ad fraud, subscription scams

Rivalry apps for men leak user personal data and driver’s license

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Google’s Genie 3: The Dawn of General AI?

FySelf, PODs, TwinH: Revolutionizing Digital Identity & Government Data Control

Beyond Zuckerberg’s Metaverse: TwinH Powers Digital Government with Berners-Lee’s New Internet Vision

The TwinH Advantage: Unlocking New Potential in Digital Government Strategies

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.