Cyber Threat Digest – 2025-09-04
🔥 Known Exploited Vulnerabilities (CISA KEV)
2 exploited vulns of note in the last 48 hours.
- CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability — TP-Link TL-WR841N (Added: 2025-09-03) — Details
- CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Multiple Routers (Added: 2025-09-03) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2024-13068 — Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing.This issue affects LimonDesk: from s1.02.14 before v1.02.17. HIGH 7.3 — Details
- CVE-2025-0878 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft LimonDesk allows Cross-Site Scripting (XSS).This issue affects… MEDIUM 4.7 — Details
- CVE-2025-26210 — An Cross-Site Scripting (XSS) vulnerability in DeepSeek R1 through V3.1 allows a remote attacker to execute arbitrary code via unspecified input fields. CRITICAL 9.8 — Details
- CVE-2025-2416 — Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypass.This issue affects LimonDesk: from s1.02.14 before v1.02.… HIGH 8.6 — Details
- CVE-2025-47421 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCRE… HIGH 8.6 — Details
- CVE-2025-9822 — SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally available. ImpactAn administrator who usua… MEDIUM 5.5 — Details
📰 Security News
Top headlines from trusted sources.
- Tire giant Bridgestone confirms cyberattack impacts manufacturing
— Thu, 04 Sep 2025 13:46:07 GMT - Microsoft says recent Windows updates cause app install issues
— Thu, 04 Sep 2025 11:57:02 GMT - Threat actors abuse X's Grok AI to spread malicious links
— Wed, 03 Sep 2025 22:01:34 GMT - US offers $10 million bounty for info on Russian FSB hackers
— Wed, 03 Sep 2025 19:01:46 GMT - Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws
— Wed, 03 Sep 2025 18:03:42 GMT - US sues robot toy maker for exposing children's data to Chinese devs
— Wed, 03 Sep 2025 17:53:32 GMT
Comments
Post a Comment