Story perspectives
Critical TP-Link Router Vulnerabilities Expose Devices to Hacks
9/6/2025
1 of 2
CISA Warns Vulnerabilities
- CISA identified two critical vulnerabilities in TP-Link routers, CVE-2025-9377 and CVE-2023-50224, requiring remediation by September 24, 2025.
- These vulnerabilities enable OS command injection and authentication bypass, risking unauthorized access and device takeover.
- Affected models, nearing end-of-life, lack manufacturer support, increasing exposure to exploits.
- CISA also highlighted a severe flaw in a TP-Link Wi-Fi extender and a WhatsApp vulnerability linked to spyware.
- Experts caution that unmanaged consumer devices elevate security risks for home and small business networks.
1 / 2
