BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

CISA Warns of Active Exploits Targeting WhatsApp, TP-Link Devices

CISA Adds High-Risk TP-Link and WhatsApp Vulnerabilities to Exploited Catalog, Urges Federal Agencies to Patch by September 2025

  • CISA added a high-risk vulnerability affecting TP-Link TL-WA855RE Wi-Fi Range Extenders to its Known Exploited Vulnerabilities catalog.
  • The security flaw, CVE-2020-24363, can let attackers gain control by resetting the device and setting a new admin password.
  • The problem has been fixed in an earlier firmware, but the device has reached end-of-life and will not get future updates.
  • A WhatsApp vulnerability (CVE-2025-55177), exploited in a targeted spyware campaign using an Apple OS flaw, was also added to the catalog.
  • Federal agencies must apply recommended fixes by September 23, 2025, to protect against ongoing threats.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two actively exploited security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2025. The first flaw impacts the TP-Link TL-WA855RE Wi-Fi Range Extender. The second targets WhatsApp through a highly-targeted spyware attack chaining a related Apple operating system vulnerability.

- Advertisement -

CISA explained that the TP-Link vulnerability, tracked as CVE-2020-24363 with a CVSS score of 8.8, allows an attacker connected to the same network to send a specially crafted command. This command triggers a device reset, letting attackers set a new admin password and get unauthorized control. Firmware version TL-WA855RE(EU)_V5_200731 fixed the issue, but the product’s end-of-life status means no further patches are expected, according to malwrforensics.

CISA stated: “This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.” The agency advises users to replace outdated Wi-Fi range extenders to ensure proper security, as continued use increases risk.

The agency also added a WhatsApp vulnerability, CVE-2025-55177. Attackers chained this flaw with an Apple iOS, iPadOS, and macOS issue, CVE-2025-43300, to launch a spyware campaign. WhatsApp reported it notified fewer than 200 users who may have been targeted. Details on the perpetrators, methods, and scale remain undisclosed, but it is suspected a commercial surveillance vendor is behind the attack.

Federal Civilian Executive Branch agencies must apply all required mitigations by September 23, 2025, to reduce their exposure to these ongoing threats. Further details on the vulnerabilities and advisories are available from CISA.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

U.S. Blocks Anthropic’s Top AI Models Over Security Fears

The U.S. government ordered Anthropic to suspend foreign access to its advanced AI models,...

Critical Splunk Vulnerability Allows Unauthenticated RCE

Splunk has patched a critical vulnerability, CVE-2026-20253, rated 9.8 on the CVSS scale, allowing...

AI Agent Bills Operator $6.5k After Wild AWS Spree

An AI agent deployed by an operator named JertLinc autonomously spun up five powerful...

Bitcoin ETF Inflows Spark Hope After 2026 Price Lows

Bitcoin has plunged to 2026 lows of under $60,000, down 50% from its October...

Investors Bet on Onchain Credit Infrastructure Over DeFi

Morpho Labs raises $175M from investors like Paradigm, aiming to become a foundational credit...

Must Read

8 Best Crypto Debit Cards For Spending Your Digital Tokens

What are | How we chose | Best crypto debit cards | Binance Card? | FAQ | Final WordsCrypto debit cards have transformed how...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading