Google security engineer discloses zero-day flaw in TP-Link smart home routers
#1
Exclamation 
Quote:A zero-day vulnerability impacting TP-Link SR20 smart home routers has been exposed publicly after the company allegedly failed to respond to a researcher's private disclosure.
 
Matthew Garrett, a Google security engineer, revealed the bug after the company failed to fix the issue within 90 days, a timeframe now established within cybersecurity which is considered to be a reasonable amount of time offered to vendors to fix reported security issues.

The security flaw is a zero-day arbitrary code execution (ACE) bug in TP-Link SR20 routers, which are dual band 2.4 GHz / 5 GHz products touted as routers suitable for controlling smart home and Internet of Things (IoT) devices while lessening the risk of bottlenecks. The SR20 also supports devices which make use of the ZigBee and Z-Wave protocols.

As documented in this Twitter conversation feed, Garrett disclosed his findings to TP-Link over 90 days ago via the firm's online security disclosure form.
 
Despite TP-Link promising researchers they would hear back within three business days, weeks later, there was no response. Attempts to contact TP-Link through other channels also failed.  

SOURCE: https://www.zdnet.com/article/google-dev...e-routers/
[-] The following 2 users say Thank You to silversurfer for this post:
  • Deep900, harlan4096
Reply
#2
Hope this will be fixed soon, this vulnerability could allow attackers to deal with files and in general to data related to the routers and this could be very dangerous. This is also worrying because IoT devices are becoming quite popular and used.
[-] The following 1 user says Thank You to Deep900 for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Vivaldi 7.8 Build 3925.62
Vivaldi 7.8 Build ...harlan4096 — 09:56
New Windows 11 Preview Adds Sysmon, Fixe...
Microsoft has rele...harlan4096 — 09:30
Android 16 February 2026 Security Update...
Google has begun t...harlan4096 — 08:59
Mozilla Firefox Browser 147.0.3
Mozilla Firefox Br...harlan4096 — 07:44
Avast 26.1.10738 & AVG 26.1.10738
Avast 26.1.10738: ...harlan4096 — 07:43

[-]
Birthdays
Today's Birthdays
avatar (48)Michaelecozy
Upcoming Birthdays
avatar (47)hapedDow
avatar (46)komriwat
avatar (38)showercurtains
avatar (49)PeterWhink
avatar (50)neuthrusBub
avatar (30)script6027529171
avatar (46)delsreehRob
avatar (44)pyotrded
avatar (41)oecmecodo
avatar (40)ShakitaSmobe
avatar (49)tsorenHievy
avatar (46)myhotseeve
avatar (46)Edwinmub
avatar (46)dimaWeami
avatar (41)svoyaEnuct
avatar (39)TranoTymn
avatar (39)MezirLal
avatar (50)listfquoto
avatar (46)dima6sarPrave
avatar (38)Michaelaburi
avatar (46)dpascoal
avatar (51)Ronaldduh
avatar (39)legalgauch
avatar (41)yposegij
avatar (44)Baihu
avatar (27)RaseinsLikes

[-]
Online Staff
Mehdi's profile Mehdi

>