Skip to content
Threat Feed

Vendor

TP-Link

6 briefs RSS
high advisory

Hard-coded RSA-512 Mesh Key in TP-Link Deco Routers

A hard-coded RSA-512 private key in TP-Link Deco mesh firmware allows adjacent attackers to impersonate trusted nodes, enabling unauthorized configuration changes and firmware modification.

Deco XE75 +2
1t 1c
high advisory

Authenticated Remote Code Execution in TP-Link Archer BE800

An authenticated remote code execution vulnerability (CVE-2026-16348) in the TP-Link Archer BE800 management interface allows attackers with administrator privileges to execute arbitrary commands via shell injection in the VPN key field.

Archer BE800 rce shell-injection router network-appliance
1t 1c
high advisory

Authenticated OS Command Injection in TP-Link Archer C20 Routers

An authenticated OS command injection vulnerability, CVE-2026-75616, in TP-Link Archer C20 v6 routers allows an administrator to achieve root-level code execution via the BPA WAN configuration interface.

Archer C20 v6 cve-2026-75616 command-injection tp-link
1t 1c
medium advisory

BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers

A commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.

Photoshop +3 iis malware maas seo fraud
2r 1t 6i
high threat

Adversaries Leveraging AI for Vulnerability Exploitation and Augmented Operations

Threat actors are leveraging AI to enhance vulnerability discovery, exploit development, defense evasion, and autonomous operations, with state-sponsored groups showing particular interest in AI-driven vulnerability research and exploit generation.

exploited Gemini +1 ai vulnerability-exploitation defense-evasion supply-chain
2r 3t
critical advisory

Mirai Campaign Exploiting CVE-2025-29635 in D-Link Routers

A new Mirai-based malware campaign is exploiting CVE-2025-29635, a command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet.

DIR-823X +1 mirai ddos rce iot
2r 4t 2c