Maximum-Severity Flaw in D-Link Routers Lets Attackers Take Over Devices With No Login Required
A stack-based buffer overflow in D-Link's DIR-822A router, rated a perfect CVSS 10.0, can be triggered remotely with no authentication and no user interaction, and a working public...
Five New TP-Link Flaws Let Attackers Hijack ISP-Managed Routers and Mesh Systems
TP-Link has disclosed five vulnerabilities affecting its carrier-supplied Aginet router, mesh, and modem lineup, the worst of which lets an attacker on the network bypass authentication entirely. Because...
Tenda Router Backdoor (CVE-2026-11405) Lets Attackers Skip Login and Seize Full Admin Control
A hardcoded authentication backdoor in Tenda FH1201, W15E, AC10, AC5, and AC6 routers (CVE-2026-11405) lets attackers log in as admin with any username. The undocumented flaw sits in...
AryStinger Botnet Hijacks 4,300+ Routers to Build Global Covert Attack Proxy Network
Researchers have uncovered AryStinger, a stealthy botnet that has hijacked over 4,300 legacy Linksys and D-Link routers by exploiting decade-old vulnerabilities. Unlike DDoS botnets, AryStinger is purpose-built for...