Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Russia’s APT28 launches “NotDoor” Outlook backdoor for companies in NATO countries

Using the GhoStredirector Hacks 65 Windows Server Rungan Backdoor and Gamshen IIS Module

JetBlue uses free in-flight internet using Amazon’s project Kuiper Satellites

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation
Identity

CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation

userBy userSeptember 3, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 3, 2025Ravi LakshmananVulnerability/Mobile Security

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday affected the TP-Link TL-WA855RE Wi-Fi Ranger Extender product, affected the known exploitation catalogue, and cited evidence of active exploitation.

The vulnerability, CVE-2020-24363 (CVSS score: 8.8) is related to cases where authentication is missing that could be abused to gain increased access to sensitive devices.

“The vulnerability allows unidentified attackers (on the same network) to send factory reset and restart TDDP_RESET POST requests,” the agency said. “Attackers can obtain incorrect access controls by setting a new administrative password.”

According to Malwrforensics, this issue has been fixed in firmware version TL-WA855RE(EU)_V5_200731. However, please note that your product has reached end-of-life (EOL) status. This means you rarely receive patches or updates. Wi-Fi Range Extender users are advised to replace the gear with a new model that addresses the issue.

Audit and subsequent

The CISA does not share details about how vulnerabilities are exploited in the wild at the scale of such attacks.

Additionally, what was added to the KEV catalog is a security flaw that WhatsApp disclosed last week (CVE-2025-55177, CVSS score: 5.4), which is used as part of highly targeted spyware campaigns by chaining chains with vulnerabilities in Apple iOS, iPados, and Macos (CVE-2025-43300, CVSS score: 8.8).

While little is known about who will be targeted and which commercial spyware vendors are behind the attack, WhatsApp told Hacker News it sent in-app threat notifications to fewer than 200 users who may have targeted it as part of its campaign.

The Federal Civil Enforcement Division (FCEB) agency recommends that by September 23, 2025, apply the necessary mitigation to both vulnerabilities that counter aggressive threats.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSalesLoft takes drift offline after OAUTH token theft hits hundreds of organizations
Next Article Offline biometric authentication and tokenisation
user
  • Website

Related Posts

Russia’s APT28 launches “NotDoor” Outlook backdoor for companies in NATO countries

September 4, 2025

Using the GhoStredirector Hacks 65 Windows Server Rungan Backdoor and Gamshen IIS Module

September 4, 2025

Cybercriminals exploit X’s Grok AI to bypass advertising protection and spread malware to millions

September 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Russia’s APT28 launches “NotDoor” Outlook backdoor for companies in NATO countries

Using the GhoStredirector Hacks 65 Windows Server Rungan Backdoor and Gamshen IIS Module

JetBlue uses free in-flight internet using Amazon’s project Kuiper Satellites

Search Google circles can now be translated when scrolling

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Smart Health, Seamless Integration: GooApps Leads the Way in 2025

Beyond Compliance: The New Era of Smart Medical Device Software Integration

Unlocking Tomorrow’s Health: Medical Device Integration

Web 3.0’s Promise: What Sir Tim Berners-Lee Envisions for the Future of the Internet

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.