Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Resolves consistency of certification for bio-based products

CERT-UA warns against C# malware attacks that drive HTA using court subpoena lures

CISA adds three D-Wind Router flaws to KEV catalog after active exploitation report

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds three D-Wind Router flaws to KEV catalog after active exploitation report
Identity

CISA adds three D-Wind Router flaws to KEV catalog after active exploitation report

userBy userAugust 6, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 6, 2025Ravi LakshmananVulnerability/Firmware Security

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three old security flaws affecting D-Link routers to its known Exploited Vulnerabilities (KEV) catalogue based on evidence of aggressive wild exploitation.

High-strength vulnerabilities from 2020 and 2022 are listed below –

CVE-2020-25078 (CVSS score: 7.5) – Unspecified vulnerability in DCS-2530L and DCS-2670L devices CVE-2020-25079 (CVSS score: 8.8) – Command injection vulnerability demonstrating vulnerability in CGI-BIN/DNS_ECNS_ENC DCS-2530L and DCS-2670L devices CVE-2020-40799 (CVSS score: 8.8) – Download code without integrity check D-Link The vulnerability in DNR-322L allows an attacker who has been authenticated to execute operating system-level commands on a device that is capable of executing operating system-level commands.

Cybersecurity

Currently, there is no details on how these shortcomings are exploited in the wild, but an advisory from the US Federal Bureau of Investigation (FBI) in December 2024 warned about the Hiatusrat campaign, which aggressively scans vulnerable webcams against CVE-2020-25078.

It is worth noting that as of November 2021, CVE-2020-40799 remains below that CVE-2020-40799 is present as the affected model has reached end-of-life (EOL) status. The fix for the other two flaws was released by D-Link in 2020.

In light of active exploitation, it is essential that federal civil enforcement sector (FCEB) agencies implement necessary mitigation procedures by August 26, 2025 to ensure their networks.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFor the first time, OpenAI models are available on AWS
Next Article CERT-UA warns against C# malware attacks that drive HTA using court subpoena lures
user
  • Website

Related Posts

CERT-UA warns against C# malware attacks that drive HTA using court subpoena lures

August 6, 2025

ClickFix Malware Campaign exploits CAPTCHAS to spread cross-platform infections

August 5, 2025

Google’s August patch fixes two exploited Qualcomm vulnerabilities in the wild

August 5, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Resolves consistency of certification for bio-based products

CERT-UA warns against C# malware attacks that drive HTA using court subpoena lures

CISA adds three D-Wind Router flaws to KEV catalog after active exploitation report

For the first time, OpenAI models are available on AWS

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

FySelf, PODs, TwinH: Revolutionizing Digital Identity & Government Data Control

Beyond Zuckerberg’s Metaverse: TwinH Powers Digital Government with Berners-Lee’s New Internet Vision

The TwinH Advantage: Unlocking New Potential in Digital Government Strategies

New Internet Era: Berners-Lee Sets the Pace as Zuckerberg Pursues Metaverse

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.