Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
320x100 Itcentric
Cyber Offensive Fundamentals 970x120 V0.1
Zero-day vulnerability affecting TP-Link routers: what to know until the patch is released

Zero-day vulnerability affecting TP-Link routers: what to know until the patch is released

5 September 2025 16:39

A new zero-day vulnerability has been discovered affecting several TP-Link router models. The issue, identified as a buffer overflow in the CPE WAN Management Protocol (CWMP) implementation, could allow an attacker to execute arbitrary code and redirect DNS requests to rogue servers.

The vulnerability was reported by an independent researcher known by the handle Mehrun (ByteRay) on May 11, 2024. TP-Link has confirmed the existence of the flaw and is working on updates to address the issue. Currently, the fix is only available for European firmware versions; the rollout for the US and other regions is ongoing.

The vulnerability resides in the SOAP SetParameterValues message processing function, where strncpy calls are executed without checking for bounds. This could lead to the possibility of arbitrary code execution if the input buffer size exceeds 3072 bytes. A real-world attack can be implemented by replacing the CWMP server and transmitting a specially crafted SOAP request.

If successfully exploited, the vulnerability can redirect DNS requests to rogue servers, silently intercept or modify unencrypted traffic, and inject malicious data into user sessions. Vulnerable router models include the Archer AX10 and Archer AX1500, which are still on sale and very popular.

TP-Link recommends users change factory administrator passwords, disable CWMP if not in use, update the firmware to the latest version, and, if possible, isolate the router from network segments. critics.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.