TP-Link has confirmed the existence of an unpatched zero-day vulnerability impacting multiple router models, as CISA warns that other router flaws have been exploited in attacks. The zero-day vulnerability was discovered by independent threat researcher Mehrun (ByteRay), who noted that he first reported it to TP-Link on May 11, 2024. The Chinese networking equipment giant confirmed to BleepingComputer that it is currently investigating the exploitability and exposure of the flaw. Though a patch is reportedly already developed for European models, work is underway to develop fixes for U.S. and global firmware versions, with no specific date estimates given. “TP-Link is aware of the recently disclosed vulnerability affecting certain router models, as reported by ByteRay,” reads the statement TP-Link Systems Inc. sent to BleepingComputer. “We take these findings seriously and have already developed a patch for impacted European models. Work is currently underway to adapt and expedite updates for U.S. and other global versions.” “Our technical team is also reviewing the reported findings in detail to confirm device exposure criteria and deployment conditions, including whether CWMP is enabled by default.” “We strongly encourage all users to keep their devices updated with the latest firmware as it becomes available via our official support channels.” The vulnerability, which doesn’t have a CVE-ID assigned to it yet, is a stack-based buffer overflow in TP-Link’s CWMP (CPE WAN Man...
New TP-Link zero-day surfaces as CISA warns other flaws are exploited
BleepingComputer
·Bill Toulas
·Published Sep 4, 2025
·Updated
Affected Software
1 affected component
TP-Link Router
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly identified zero-day vulnerability in TP-Link routers and related warnings from CISA regarding other exploited router flaws.
2
What security implications are discussed?
The article highlights the risk posed by the unpatched TP-Link zero-day vulnerability and the potential for exploitation of other known router flaws.
3
What products or software are affected?
The affected products include multiple models of TP-Link routers.
4
Who confirmed the existence of the zero-day vulnerability?
TP-Link has confirmed the existence of the unpatched zero-day vulnerability.
5
What organization issued a warning in relation to the vulnerability?
CISA issued a warning about the exploitation of other router flaws and the TP-Link zero-day vulnerability.