CISA alerts on TOTOLINK AX1800 unauthenticated telnet flaw
TOTOLINK AX1800 routers have an unauthenticated HTTP endpoint that can enable telnet and allow remote root code execution.
Decision Insights Threat Desk • December 9, 2025
TOTOLINK AX1800 routers have an unauthenticated HTTP endpoint that can enable telnet and allow remote root code execution.
Decision Insights Threat Desk • December 9, 2025
CISA issued three ICS advisories covering U-Boot, a Festo LX appliance, and India-based CCTV cameras.
Decision Insights Threat Desk • December 8, 2025
CISA added CVE-2022-37055 and CVE-2025-66644 to its Known Exploited Vulnerabilities Catalog.
Decision Insights Threat Desk • December 5, 2025
CISA added CVE-2025-55182, a remote code execution flaw in Meta React Server Components, to its Known Exploited Vulnerabilities Catalog.
Decision Insights Threat Desk • December 5, 2025
Duc disk management tool patched in version 1.4.6 after a stack-based buffer overflow allowed out-of-bounds memory reads.
Decision Insights Threat Desk • December 4, 2025
CISA reports PRC state-sponsored actors using BRICKSTORM backdoor against VMware vSphere and Windows to maintain persistent access.