Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TP-Link Router Zero-Day RCE Vulnerability Exploited Bypassing ASLR Protections

TP-Link Router Zero-Day RCE Vulnerability Exploited Bypassing ASLR Protections

Posted on September 18, 2025September 18, 2025 By CWS

A crucial zero-day distant code execution (RCE) vulnerability, recognized as CVE-2025-9961, has been found in TP-Hyperlink routers.

Safety analysis agency ByteRay has launched a proof-of-concept (PoC) exploit, demonstrating how attackers can bypass Tackle House Format Randomization (ASLR) protections to realize full management over affected units.

The vulnerability resides within the router’s Buyer Premises Gear (CPE) WAN Administration Protocol (CWMP) binary, a element of the TR-069 protocol utilized by service suppliers for distant machine administration.

Technical Breakdown of the Exploit

The core of the vulnerability is a stack-based buffer overflow throughout the cwmp course of. Researchers at ByteRay discovered that by sending a malicious request, they might overwrite this system counter (PC) and seize management of the execution circulate.

Nonetheless, the presence of ASLR, a safety characteristic that randomizes the reminiscence addresses of key information areas, offered a major hurdle.

Because the exploit didn’t contain an info leak to reveal reminiscence layouts, the researchers devised a brute-force technique. They repeatedly guessed the bottom deal with of the usual C library (libc) to find the system() operate.

Assault Situation

An incorrect guess would crash the cwmp service, however the researchers famous that an attacker with entry to the TP-Hyperlink net panel may merely restart the service, making the brute-force assault sensible.

The assault workflow requires the router to be configured to simply accept the attacker’s customized Auto Configuration Server (ACS). The exploit is delivered by a SetParameterValues request containing the payload.

The ultimate payload makes use of a return-to-libc (ret2libc) approach to name the system() operate with a command argument.

This command instructs the router to obtain and execute a malicious binary (e.g., a reverse shell) from an attacker-controlled server, granting the attacker full distant entry.

Discovery and PoC Launch

The ByteRay analysis workforce made the invention. Throughout their evaluation, they encountered an issue the place the usual GenieACS platform corrupted the binary payload, stopping profitable exploitation. This pressured them to develop a customized ACS emulator able to faithfully transmitting the exploit code.

The workforce has printed an in depth technical write-up and the complete exploit code on GitHub. They state the discharge is meant for instructional functions and safety analysis, permitting directors to check their very own units. Unauthorized use of different methods is against the law.

PoC Exploit

This vulnerability is crucial, as profitable exploitation permits for full distant code execution on the router. This might allow an attacker to intercept visitors, launch additional assaults on the native community, or enlist the machine in a botnet.

The analysis underscores the safety dangers related to network-facing administration protocols like TR-069, the place even minor parsing errors can escalate into extreme threats.

The exploit highlights that safety mitigations like ASLR can generally be bypassed with inventive assault methods.

Customers of TP-Hyperlink routers are suggested to watch for firmware updates from the seller and apply them as quickly as they turn out to be obtainable to patch this vulnerability.

Discover this Story Attention-grabbing! Observe us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates.

Cyber Security News Tags:ASLR, Bypassing, Exploited, Protections, RCE, Router, TPLink, Vulnerability, ZeroDay

Post navigation

Previous Post: Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions
Next Post: Pixie Dust Wi-Fi Attack Exploits Routers WPS to Obtain PIN and Connect With Wireless Network

Related Posts

Stealthy CastleLoader Malware Attacking US-Based Government Entities Stealthy CastleLoader Malware Attacking US-Based Government Entities Cyber Security News
5 Common Back-to-School Online Scams Powered Using AI and How to Avoid Them 5 Common Back-to-School Online Scams Powered Using AI and How to Avoid Them Cyber Security News
Betterleaks: The Advanced Open-Source Secrets Scanner Betterleaks: The Advanced Open-Source Secrets Scanner Cyber Security News
New BOF Tool Exploits Microsoft Teams’ Cookie Encryption allowing Attackers to Access User Chats New BOF Tool Exploits Microsoft Teams’ Cookie Encryption allowing Attackers to Access User Chats Cyber Security News
Microsoft Warns of Hackers Using ClickFix Technique to Attack Windows and macOS Devices Microsoft Warns of Hackers Using ClickFix Technique to Attack Windows and macOS Devices Cyber Security News
GrayCharlie Targets WordPress Sites with Malicious Scripts GrayCharlie Targets WordPress Sites with Malicious Scripts Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • India to Prohibit Chinese CCTV Sales by 2026
  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark