Tag: router
-
Router-Modell DWR-M961 Link patcht kritische Command Injection
First seen on security-insider.de Jump to article: www.security-insider.de/d-link-dwr-m961-15-sicherheitsluecken-root-command-injection-a-2d8b3d1f7d18d7ecdbc347a22880d962/
-
TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These vulnerabilities could enable attackers to execute arbitrary operating system commands with root privileges. The security advisory, updated on August 24, 2026, pertains to the Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 devices.…
-
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/
-
Cudy WR3000 Router Flaws Can Be Chained to Gain Root Access
Public exploit tools for 2 Cudy WR3000 flaws can forge JWTs, bypass MQTT authentication, and remotely execute operating-system commands as root on the router. First seen on hackread.com Jump to article: hackread.com/cudy-wr3000-router-flaws-chained-root-access/
-
Enterprise Network Security Solution
A traditional corporate network may once have consisted primarily of office computers, servers, switches, routers, and a centralized data center. Today, organizations operate across cloud platforms, remote offices, SaaS applications, mobile devices, IoT systems, endpoints, APIs, data centers, and operational technology environments. Employees can access business resources from almost anywhere. Applications may be distributed across…
-
Erkennung von Einbrechern: Millionen von Routern werden zu Überwachungsgeräten
Einbrecher lassen sich anhand von WLAN-Signalen erkennen. In den USA wird ein entsprechendes Router-Feature jetzt großflächig ausgerollt. First seen on golem.de Jump to article: www.golem.de/news/erkennung-von-einbrechern-millionen-von-routern-werden-zu-ueberwachungsgeraeten-2608-212080.html
-
D-Link DWR-M961 Router Hit by 15 Command Injection and Buffer Overflow Vulnerabilities
D-Link has disclosed and patched 15 Common Vulnerabilities and Exposures (CVEs) affecting its DWR-M961 4G/LTE router, specifically hardware revision C1. This follows the discovery of multiple command injection and buffer overflow vulnerabilities in the device’s web management components. These vulnerabilities affect non-US DWR-M961 devices running firmware versions 1.1.2_C1_202602110044 and earlier revisions. D-Link DWR-M961 Router Flaw…
-
Comcast turns your Xfinity WiFi into a home motion detector
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/comcast-turns-your-xfinity-wifi-into-a-home-motion-detector/
-
Comcast adds motion sensing to millions of its newer routers, with a privacy catch
A new feature added to Comcast’s newest routers can detect if there is motion is inside your home without needing traditional motion sensors. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/18/comcast-adds-motion-sensing-to-millions-of-its-newer-routers-with-a-privacy-catch/
-
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai’s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a…
-
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over.Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and…
-
âš¡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed…
-
China-Linked Surveillance Platform Spans at Least 117 Servers, Targets Routers
LightSpy, a China-linked surveillance platform, has grown into an operation using at least 117 servers with verified router infections. At Black Hat USA, Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov said LightSpy has been identified in more than 13 countries, growing well beyond the spyware, active since at least 2018 and publicly documented in…
-
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access
A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of…
-
Breach Roundup: Water Utilities in 12 US States Hit
Also, Chinese-Made SOHO Routers Contain Trojan, AI Fuels Cybercrime Across Africa. This week: water utilities in 12 U.S. states hit, Trojans in Chinese SOHO routers, banned Chinese companies in U.S. networks, AI fueled cybercrime in Africa, a U.K. police legal database breached, IBM Langflow AI flaw, a cyberattack delayed orders at a Dutch retailer and…
-
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available from Zbtlink that span more than 2 years. The backdoors are designed such that they start automatically and attempt to…
-
VulnCheck Warns That Chinese Zbtlink Routers Include a Backdoor
VulnCheck researcher say at least 100,000 Chinese-made Zbtlink routers around the world may include an intentionally implanted backdoor dubbed “Endlessdoors” that could give threat actors access to devices on the network. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/vulncheck-warns-that-chinese-zbtlink-routers-include-a-backdoor/
-
15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/forescout-tp-link-omada-vulnerabilities/
-
TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high. TP-Link TL-WR940N Router Flaw According…

