Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Silicon-based Lewis acids can break down PFAS chemicals

CloudFlare blocks record-breaking 11.5 TBPS DDOS attacks

Offline biometric authentication and tokenisation

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation
Identity

CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation

userBy userSeptember 3, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 3, 2025Ravi LakshmananVulnerability/Mobile Security

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday affected the TP-Link TL-WA855RE Wi-Fi Ranger Extender product, affected the known exploitation catalogue, and cited evidence of active exploitation.

The vulnerability, CVE-2020-24363 (CVSS score: 8.8) is related to cases where authentication is missing that could be abused to gain increased access to sensitive devices.

“The vulnerability allows unidentified attackers (on the same network) to send factory reset and restart TDDP_RESET POST requests,” the agency said. “Attackers can obtain incorrect access controls by setting a new administrative password.”

According to Malwrforensics, this issue has been fixed in firmware version TL-WA855RE(EU)_V5_200731. However, please note that your product has reached end-of-life (EOL) status. This means you rarely receive patches or updates. Wi-Fi Range Extender users are advised to replace the gear with a new model that addresses the issue.

Audit and subsequent

The CISA does not share details about how vulnerabilities are exploited in the wild at the scale of such attacks.

Additionally, what was added to the KEV catalog is a security flaw that WhatsApp disclosed last week (CVE-2025-55177, CVSS score: 5.4), which is used as part of highly targeted spyware campaigns by chaining chains with vulnerabilities in Apple iOS, iPados, and Macos (CVE-2025-43300, CVSS score: 8.8).

While little is known about who will be targeted and which commercial spyware vendors are behind the attack, WhatsApp told Hacker News it sent in-app threat notifications to fewer than 200 users who may have targeted it as part of its campaign.

The Federal Civil Enforcement Division (FCEB) agency recommends that by September 23, 2025, apply the necessary mitigation to both vulnerabilities that counter aggressive threats.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSalesLoft takes drift offline after OAUTH token theft hits hundreds of organizations
Next Article Offline biometric authentication and tokenisation
user
  • Website

Related Posts

CloudFlare blocks record-breaking 11.5 TBPS DDOS attacks

September 3, 2025

SalesLoft takes drift offline after OAUTH token theft hits hundreds of organizations

September 3, 2025

Lazarus Group extends malware arsenal with Pondrat, Themeforestrat and Remotepe

September 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Silicon-based Lewis acids can break down PFAS chemicals

CloudFlare blocks record-breaking 11.5 TBPS DDOS attacks

Offline biometric authentication and tokenisation

CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Beyond Compliance: The New Era of Smart Medical Device Software Integration

Unlocking Tomorrow’s Health: Medical Device Integration

Web 3.0’s Promise: What Sir Tim Berners-Lee Envisions for the Future of the Internet

TwinH’s Paves Way at Break The Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.