Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Maternal PFAS levels are linked to children’s brain development

F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More

Amazon DNS outage destroys large portions of the Internet

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation
Identity

CISA adds TP-Link and WhatsApp flaws to KEV catalog amid aggressive exploitation

userBy userSeptember 3, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 3, 2025Ravi LakshmananVulnerability/Mobile Security

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday affected the TP-Link TL-WA855RE Wi-Fi Ranger Extender product, affected the known exploitation catalogue, and cited evidence of active exploitation.

The vulnerability, CVE-2020-24363 (CVSS score: 8.8) is related to cases where authentication is missing that could be abused to gain increased access to sensitive devices.

“The vulnerability allows unidentified attackers (on the same network) to send factory reset and restart TDDP_RESET POST requests,” the agency said. “Attackers can obtain incorrect access controls by setting a new administrative password.”

According to Malwrforensics, this issue has been fixed in firmware version TL-WA855RE(EU)_V5_200731. However, please note that your product has reached end-of-life (EOL) status. This means you rarely receive patches or updates. Wi-Fi Range Extender users are advised to replace the gear with a new model that addresses the issue.

Audit and subsequent

The CISA does not share details about how vulnerabilities are exploited in the wild at the scale of such attacks.

Additionally, what was added to the KEV catalog is a security flaw that WhatsApp disclosed last week (CVE-2025-55177, CVSS score: 5.4), which is used as part of highly targeted spyware campaigns by chaining chains with vulnerabilities in Apple iOS, iPados, and Macos (CVE-2025-43300, CVSS score: 8.8).

While little is known about who will be targeted and which commercial spyware vendors are behind the attack, WhatsApp told Hacker News it sent in-app threat notifications to fewer than 200 users who may have targeted it as part of its campaign.

The Federal Civil Enforcement Division (FCEB) agency recommends that by September 23, 2025, apply the necessary mitigation to both vulnerabilities that counter aggressive threats.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSalesLoft takes drift offline after OAUTH token theft hits hundreds of organizations
Next Article Offline biometric authentication and tokenisation
user
  • Website

Related Posts

F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More

October 20, 2025

131 Chrome extensions found to be hijacking WhatsApp Web in massive spam campaign

October 20, 2025

MSS claims NSA used 42 cyber tools in multi-stage attack on Beijing Time System

October 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Maternal PFAS levels are linked to children’s brain development

F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More

Amazon DNS outage destroys large portions of the Internet

131 Chrome extensions found to be hijacking WhatsApp Web in massive spam campaign

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.