• News/
  • https://www.bleepingcomputer.com/news/security/new-tp-link-zero-day-surfaces-as-cisa-warns-other-flaws-are-exploited/

New TP-Link zero-day surfaces as CISA warns other flaws are exploited

BleepingComputer
·
Bill Toulas
·
Published Sep 4, 2025
·
Updated

TP-Link has confirmed the existence of an unpatched zero-day vulnerability impacting multiple router models, as CISA warns that other router flaws have been exploited in attacks. The zero-day vulnerability was discovered by independent threat researcher Mehrun (ByteRay), who noted that he first reported it to TP-Link on May 11, 2024. The Chinese networking equipment giant confirmed to BleepingComputer that it is currently investigating the exploitability and exposure of the flaw. Though a patch is reportedly already developed for European models, work is underway to develop fixes for U.S. and global firmware versions, with no specific date estimates given. “TP-Link is aware of the recently disclosed vulnerability affecting certain router models, as reported by ByteRay,” reads the statement TP-Link Systems Inc. sent to BleepingComputer. “We take these findings seriously and have already developed a patch for impacted European models. Work is currently underway to adapt and expedite updates for U.S. and other global versions.” “Our technical team is also reviewing the reported findings in detail to confirm device exposure criteria and deployment conditions, including whether CWMP is enabled by default.” “We strongly encourage all users to keep their devices updated with the latest firmware as it becomes available via our official support channels.” The vulnerability, which doesn’t have a CVE-ID assigned to it yet, is a stack-based buffer overflow in TP-Link’s CWMP (CPE WAN Man...

Read full article

Affected Software

1 affected component
TP-Link Router
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly identified zero-day vulnerability in TP-Link routers and related warnings from CISA regarding other exploited router flaws.

2

What security implications are discussed?

The article highlights the risk posed by the unpatched TP-Link zero-day vulnerability and the potential for exploitation of other known router flaws.

3

What products or software are affected?

The affected products include multiple models of TP-Link routers.

4

Who confirmed the existence of the zero-day vulnerability?

TP-Link has confirmed the existence of the unpatched zero-day vulnerability.

5

What organization issued a warning in relation to the vulnerability?

CISA issued a warning about the exploitation of other router flaws and the TP-Link zero-day vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203