CISA Adds TP-Link and WhatsApp Flaws to KEV Catalog Amid Active Exploitation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-24363 | Missing Authentication in TP-Link TL-WA855RE Allows Unauthenticated Factory Reset CVE-2020-24363 is a missing-authentication flaw (CWE-306) in the TP-Link TL-WA855RE Wi-Fi range extender, where the critical TDDP reset function can be invoked without any credentials. An unauthenticated attacker who is on the same network as the device can send a TDDP_RESET POST request, forcing a factory reset and reboot. After the reset, the attacker can set a new administrative password, taking over the extender and gaining incorrect access control. Only TP-Link TL-WA855RE devices are listed as affected, and many of these units are end-of-life or end-of-service. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-02, confirming exploitation in the wild, and EPSS assigns a 20.7% probability of exploitation in the next 30 days (97th percentile). Do: Inventory networks for TL-WA855RE extenders; if a firmware update is available from TP-Link, apply it, otherwise follow the KEV required action and discontinue use or replace the device, especially since many units are EoL/EoS. As interim mitigation, restrict or segment LAN access to the extender, since exploitation requires the attacker to be on the same network. Given the KEV listing and 20.7% EPSS, treat remediation as time-sensitive under BOD 22-01 guidance. | 8.8 | 21% | KEV |
| mass≈1M devices in use (long-running best-selling consumer Wi-Fi range extender) | |
| CVE-2025-43300 | Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/O CVE-2025-43300 is an out-of-bounds write (CWE-787) in the Image I/O (ImageIO) framework used by Apple iOS, iPadOS, and macOS. It can be triggered when a device processes a specially crafted image file, corrupting memory in the image-parsing process. Successful exploitation may cause application crashes or allow arbitrary code execution with the privileges of the application handling the image. Because ImageIO is a core system component on essentially every Apple device, virtually all users of iPhones, iPads, and Macs are exposed. The flaw is being exploited in the wild — CISA added it to the KEV catalog on 2025-08-21, mandating patching per BOD 22-01 for federal agencies — and EPSS estimates a 22% probability of exploitation in the next 30 days (98th percentile); no public PoC is known and ransomware use is unconfirmed. Do: Apply Apple's security updates for iOS, iPadOS, and macOS issued in August 2025 (e.g., iOS 18.6.1 / iPadOS 18.6.1 and macOS Sequoia 15.6.1) on all devices, prioritizing user-facing fleets and agencies bound by BOD 22-01 deadlines. Until devices are patched, exercise caution with images from untrusted sources (email, messaging, web content), since no compensating mitigations are specified. Note that the source data does not enumerate exact affected builds, so verify coverage against Apple's advisory and CISA KEV required actions. | 10.0 | 22% | KEV PoC |
| mass>1 billion active Apple devices (ImageIO is a core framework on all iOS/iPadOS/macOS devices; Apple's active device base exceeds 2 billion) | |
| CVE-2025-55177 | Incorrect Authorization in WhatsApp Linked-Device Sync Used in Targeted Spyware Attacks CVE-2025-55177 is an incorrect authorization flaw (CWE-863) in how WhatsApp for iOS, WhatsApp Business for iOS, and WhatsApp for Mac validate linked device synchronization messages, allowing an unrelated user to trigger processing of content from an arbitrary URL on a target's device. An attacker can reach a vulnerable client through the messaging channel without normal authorization checks, causing the app to fetch or process attacker-chosen content. On its own the flaw carries only partial confidentiality and integrity impact (CVSS 5.4), but Meta assesses it was chained with an Apple OS vulnerability (CVE-2025-43300) in a sophisticated attack against specific, targeted users. Users running WhatsApp for iOS before 2.25.21.73, WhatsApp Business for iOS before 2.25.21.78, or WhatsApp for Mac before 2.25.21.78 are affected. The flaw was added to CISA's KEV catalog on 2025-09-02 amid reports of highly targeted zero-day attacks, though no public proof-of-concept is known and use in ransomware campaigns has not been reported. Do: Update WhatsApp for iOS to v2.25.21.73 or later, WhatsApp Business for iOS to v2.25.21.78 or later, and WhatsApp for Mac to v2.25.21.78 or later. Also apply Apple's backported OS fix for CVE-2025-43300, since the two flaws were combined in the observed attack chain. Review and re-link WhatsApp companion devices if compromise is suspected; federal agencies must follow BOD 22-01 required-action deadlines per the KEV listing. | 5.4 | 4% | KEV |
| masshundreds of millions of users (WhatsApp's multi-billion user base includes a very large iOS/macOS install base) |
Full article325 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 03, 2025Vulnerability / Mobile Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity security flaw impacting TP-Link TL-WA855RE Wi-Fi Ranger Extender products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, CVE-2020-24363 (CVSS score: 8.8), concerns a case of missing authentication that could be abused to obtain elevated access to the susceptible device.
"This vulnerability could allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot," the agency said. "The attacker can then obtain incorrect access control by setting a new administrative password."
According to malwrforensics, the issue has been fixed with firmware version TL-WA855RE(EU)_V5_200731. However, it bears noting that the product has reached end-of-life (EoL) status, meaning it's unlikely to receive any patches or updates. Users of the Wi-Fi range extender are advised to replace their gear with a newer model for optimal protection.
CISA has not shared any details on how the vulnerability is being exploited in the wild, by whom, or on the scale of such attacks.
Also added to the KEV catalog is a security flaw that WhatsApp disclosed last week (CVE-2025-55177, CVSS score: 5.4) as having been exploited as part of a highly-targeted spyware campaign by chaining it with an Apple iOS, iPadOS, and macOS vulnerability (CVE-2025-43300, CVSS score: 8.8).
Not much is known about who was targeted and which commercial spyware vendor is behind the attacks, but WhatsApp told The Hacker News that it sent in-app threat notifications to less than 200 users who may have been targeted as part of the campaign.
Federal Civilian Executive Branch (FCEB) agencies are advised to apply the necessary mitigations by September 23, 2025, for both the vulnerabilities to counter active threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/09/cisa-adds-tp-link-and-whatsapp-flaws-to.html