Apple and TP-Link Vulnerabilities Added to CISA’s KEV List Amid Spyware Scandal

Listen to this Post

Featured Image
National Security Alert as Exploits Hit Apple Devices and TP-Link Routers

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include two critical threats—one affecting Apple’s Messages app, and the other targeting TP-Link routers. These newly flagged flaws are not just theoretical; both have been actively exploited in the wild, heightening concerns over digital surveillance and infrastructure vulnerabilities.

One of the key vulnerabilities, CVE-2025-43200, targets Apple’s Messages app and was used in a zero-click attack. This flaw was exploited to deploy Paragon’s Graphite spyware, a tool designed for clandestine surveillance. Apple released patches for multiple operating systems—including iOS, macOS, watchOS, and visionOS—on February 10, 2025, to mitigate this threat. A related vulnerability, CVE-2025-24200, impacting WhatsApp, was also patched at the same time after it was exploited in highly sophisticated attacks.

Citizen Lab, an organization specializing in digital rights and cyber forensics, confirmed the Graphite spyware campaign affected at least two European journalists. Forensic evidence linked their iPhones to the same spyware server. One of the victims, journalist Ciro Pellegrino, was officially notified by Apple of the compromise in April 2025.

In a surprising turn of events, Paragon publicly accused the Italian government of rejecting its cooperation offer in investigating the spyware’s misuse. The company then decided to terminate all contracts in Italy—marking an unprecedented move in the spyware industry.

The second newly listed flaw by CISA involves TP-Link routers (models TL-WR940N, TL-WR841N, TL-WR740N). Identified as a command injection vulnerability, this flaw resides in the /userRpm/WlanNetworkRpm component. Given that these routers are commonly used in homes and small offices, the risk is substantial.

As part of Binding Operational Directive 22-01, all U.S. federal agencies are required to patch these vulnerabilities by July 7, 2025. Security experts are also urging private organizations to review their infrastructures and take immediate action.

What Undercode Say:

This incident is a glaring reminder of how state-grade cyberweapons continue to blur the line between lawful surveillance and covert intrusion. The Apple zero-click vulnerability—exploited without the user ever clicking a link—demonstrates just how far spyware developers have come in weaponizing legitimate applications. Messages and WhatsApp, apps that dominate personal and professional communications, became silent entry points for highly sophisticated attacks.

What makes CVE-2025-43200 especially dangerous is its zero-click nature, which means no user interaction was required to compromise the device. Such attacks are typically reserved for high-value targets—activists, journalists, political dissidents. The inclusion of this flaw in CISA’s KEV list confirms both its severity and widespread concern among security agencies.

The response by Paragon, a surveillance tech company, is equally telling. By severing contracts with Italy, the company is attempting to distance itself from potential misuse of its spyware—a PR move or a genuine ethical stand? That remains unclear. Nonetheless, it is the first public fallout between a spyware vendor and a state actor, and it sets a new precedent in the global spyware debate.

Turning to TP-Link, while less dramatic than a spyware scandal, the command injection flaw is no less dangerous. These routers are inexpensive, ubiquitous, and often found in environments lacking rigorous cybersecurity oversight. The vulnerability allows attackers to inject system commands remotely, potentially leading to network-wide compromise.

The decision by CISA to act quickly and publicly list these vulnerabilities is a positive sign of proactive defense. Still, with cyberattacks increasing in frequency and complexity, patching alone isn’t enough. This situation calls for better supply-chain transparency, more responsible disclosure processes, and greater pressure on manufacturers to push updates swiftly.

Most critically, this highlights a dangerous trend: spyware is no longer in the shadows. It’s being used in coordinated, state-backed campaigns—and even when exposed, accountability remains rare. Whether through legislative action or technical defenses, it’s clear the international community must take a more unified approach to confronting digital surveillance abuses.

🔍 Fact Checker Results

✅ CVE-2025-43200 is officially confirmed by Apple as exploited in the wild.
✅ Citizen Lab has verified infections linked to Paragon’s spyware.
✅ TP-Link router vulnerability is a known and active command injection flaw listed by CISA.

📊 Prediction

In the coming months, we’re likely to see a wave of patch mandates not only for federal agencies but also across private sectors handling sensitive data. More spyware campaigns will be uncovered, especially as investigative groups dig deeper into cases like the Paragon/Italy fallout. Expect stricter international scrutiny on spyware vendors and rising demand for anti-surveillance tools, especially for journalists and human rights activists. TP-Link may issue firmware patches, but the large install base and slow update habits could leave many users exposed well into 2026.

References:

Reported By: securityaffairs.com
Extra Source Hub:
https://www.quora.com/topic/Technology
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram