ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Apple products, and TP-Link routers flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-43200CVE-2023-33538CVE-2025-24200

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-33538
Command Injection in TP-Link TL-WR940N, TL-WR841N, TL-WR740N Routers

CVE-2023-33538 is a command injection flaw (CWE-77) in the /userRpm/WlanNetworkRpm component of the web management interface on several legacy TP-Link routers. An attacker who can reach the router's management interface and send crafted requests to that component can cause the device to execute arbitrary operating-system commands. Successful exploitation typically gives the attacker full control of the router, enabling traffic manipulation, DNS hijacking, or pivoting into the connected network. Only the named hardware revisions are affected — TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 — and these products may be end-of-life or end-of-service, meaning fixes may be limited or unavailable. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16, indicating exploitation in the wild, and its high EPSS score (41.9%, 99th percentile) points to substantial near-term exploitation risk.

Do: Inventory for these models and check the hardware version on the device label (TL-WR940N V2/V4, TL-WR841N V8/V10, TL-WR740N V1/V2), then apply TP-Link's mitigations or firmware updates per vendor instructions for that hardware version if still available. Because the products may be end-of-life or end-of-service, prioritize disabling remote/WAN access to the router's management interface, restrict it to trusted networks, and plan replacement of any unit still in service where mitigations are unavailable. CISA's required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance (for federal agencies), or discontinue use of the product.

8.842% KEV PoC ×2
  • TP-Link TL-WR940N V2, V4
  • TP-Link TL-WR841N V8, V10
  • TP-Link TL-WR740N V1, V2
masslikely 1M+ affected devices worldwide (precise count unknown)
CVE-2025-24200
Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode

CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12.

Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product.

6.14% KEV
  • Apple iOS (iPhone) Versions prior to the fixed releases in each branch: iOS < 15.8.4, iOS < 16.7.11, and iOS < 18.3.1
  • Apple iPadOS (iPad) Versions prior to the fixed releases in each branch: iPadOS < 15.8.4, iPadOS < 16.7.11, iPadOS < 17.7.5, and iPadOS < 18.3.1
mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure)
CVE-2025-43200
Apple iCloud Link media-processing logic flaw exploited in targeted attacks

CVE-2025-43200 is a logic issue in Apple's operating systems that occurs when processing a maliciously crafted photo or video shared via an iCloud Link (CISA catalogs it as an unspecified vulnerability across Apple iOS, iPadOS, macOS, visionOS, and watchOS). An attacker must get a user to open the crafted shared-media link, and the CVSS 4.2 score indicates network delivery with high attack complexity, user interaction, and low-severity confidentiality and integrity impact, making the flaw most useful as a step in a larger attack chain. Apple states the issue was exploited in an "extremely sophisticated attack against specific targeted individuals," and related reporting links the February 2025 updates to actively exploited WebKit flaws and a Paragon spyware campaign against European journalists. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-06-16; no public proof-of-concept is known, and EPSS estimates roughly a 1.0% chance of further exploitation in the next 30 days (62nd percentile). Anyone running iOS/iPadOS 15-18, macOS Ventura through Sequoia, visionOS, or watchOS on versions older than the listed fixes is affected.

Do: Update iOS to 15.8.4, 16.7.11, or 18.3.1; iPadOS to 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable; macOS to Sequoia 15.3.1, Sonoma 14.7.4, or Ventura 13.7.4; visionOS to 2.3.1; and watchOS to 11.3.1. Until patched, treat iCloud Links (shared photo/video links) from unknown senders with caution and use MDM to identify fleets still running pre-fix versions. US federal agencies must apply the vendor fixes per BOD 22-01 requirements given the KEV listing, and organizations at risk of targeted spyware should hunt for signs of post-exploitation on affected devices.

4.21% KEV
  • Apple iOS Versions prior to 15.8.4, 16.7.11, and 18.3.1 (fixed in iOS 15.8.4, 16.7.11, 18.3.1)
  • Apple iPadOS Versions prior to 15.8.4, 16.7.11, 17.7.5, and 18.3.1 (fixed in iPadOS 15.8.4, 16.7.11, 17.7.5, 18.3.1)
  • Apple macOS Versions prior to Ventura 13.7.4, Sonoma 14.7.4, and Sequoia 15.3.1 (fixed in those releases)
  • +2 more
masshundreds of millions to ~2 billion active Apple devices on affected OS versions
Full article511 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple products, and TP-Link routers flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple products, and TP-Link routers flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-43200 Apple Multiple Products Unspecified Vulnerability
  • CVE-2023-33538 (CVSS score 8.8) TP-Link Multiple Routers Command Injection Vulnerability

Last week, Apple confirmed that the now-patched vulnerability CVE-2025-43200 in its Messages app was actively exploited in the wild to target journalists with Paragon’s Graphite spyware.

The IT giant addressed the flaw CVE-2025-43200 on February 10, 2025, with the release of iOS 18.3.1, iPadOS 18.3.1iPadOS 17.7.5macOS Sequoia 15.3.1macOS Sonoma 14.7.4macOS Ventura 13.7.4watchOS 11.3.1, and visionOS 2.3.1. The same versions also addressed the WhatsApp vulnerability CVE-2025-24200 that was exploited in “extremely sophisticated” targeted attacks.

“A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link.” reads the advisory published by the company. “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

The company addressed this vulnerability by implementing improved checks.

This week, Citizen Lab confirmed that Paragon’s Graphite spyware was used to hack fully updated iPhones, targeting at least two journalists in Europe. The group found forensic evidence showing the phones had communicated with the same spyware server. Apple quietly alerted the victims earlier this year, marking the first confirmed case of Paragon’s tools being used in real-world attacks.

On April 29, 2025, Apple alerted select iOS users of spyware targeting. Forensic analysis confirmed that two journalists, including Ciro Pellegrino, were infected with Paragon’s Graphite spyware. Both cases were linked to the same attacker. Apple has since patched the zero-click exploit used in the attack, now tracked the flaw as CVE-2025-43200, in iOS version 18.3.1.

Early this week, Paragon accused the Italian government of refusing its offer to help investigate spyware use against a journalist. The company said this led to its decision to end contracts in Italy. Paragon claimed it proposed a way to verify if its tools were misused, but authorities declined. This marks the first time a spyware firm publicly cut ties with a client over alleged abuse. Paragon confirmed the statement’s accuracy but declined further comment.

The second vulnerability added by CISA to its KeV catalog is a command injection vulnerability in the /userRpm/WlanNetworkRpm component that impacts several TP-Link router models (TL-WR940N, TL-WR841N, TL-WR740N).

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by July 7, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179086/security/u-s-cisa-adds-apple-products-and-tp-link-routers-flaws-to-its-known-exploited-vulnerabilities-catalog.html