Security News

TP-Link router zero-day that offers your network up to hackers
2019-04-02 11:48

Downgrade attack lets any user take over - just ask for old-style access to the debugging port and you won't need a password

0-Day in TP-Link SR20 Routers Allows Command Execution
2019-04-01 05:29

An unpatched vulnerability in the TP-Link SR20 smart hub and router can be exploited to achieve arbitrary command execution, a security researcher has discovered.  read more

Zero-Day Bug Lays Open TP-Link Smart Home Router
2019-03-29 16:06

However, an attacker would need to already be on the local network to be successful.

Cisco Improperly Patched Exploited Router Vulnerabilities
2019-03-29 13:36

Cisco this week revealed that patches released in January for vulnerabilities in Small Business RV320 and RV325 routers were incomplete. The flaws have been exploited in live attacks.  read more

TP-Link 'smart' router proves to be anything but smart – just like its maker: Zero-day vuln dropped after silence
2019-03-28 19:40

Google security engineer emits SR20 PoC exploit after manufacturer fails to respond TP-Link's all-in-one SR20 Smart Home Router allows arbitrary command execution from a local network connection,...

Cisco botched patches for its RV320/RV325 routers
2019-03-28 10:42

Cisco RV320 and RV325 WAN VPN routers are still vulnerable to attack through two flaws that Cisco had supposedly patched. #Cisco Small Business Routers still vulnerable to remote code execution &...

Huawei bungled router security, leaving kit open to botnets, despite alert from ISP years prior
2019-03-28 09:15

Chinese kit slinger was told of UPnP flaw in 2013, didn't do too much about it Exclusive Huawei bungled its response to warnings from an ISP's code review team about a security vulnerability...

Cisco Releases Flood of Patches for IOS XE and Small Business Routers
2019-03-27 21:48

The networking giant issued 27 patches impacting a wide range of its products running the ISO XE software.

Did you hear the one about Cisco routers using strcpy insecurely for login authentication? Makes you go AAAAA-AAAAAAAA *segfault*
2019-03-01 18:02

RV110W, RV130W and RV215W models need patching Cisco has patched three of its RV-series routers after Pen Test Partners (PTP) found them using hoary old C function strcpy insecurely in login...