TSI A.I CyberSecurity Scoring
TSI
Company Information
Website:https://www.tp-link.com/us/
Employees number:382
Number of followers:31,892
NAICS:334
Industry Type:Computers and Electronics Manufacturing
Homepage:tp-link.com
TSI Risk Score (AI oriented)
Between 600 and 649
TSIComputers and Electronics Manufacturing
Updated:
03/08/2026
03/08/2026
646/1000
Poor
Caa
TSI Global Score (TPRM)
xxxx
TSIComputers and Electronics Manufacturing
Score locked

TSIPoor
Current Score
646Caa (POOR)
01000
10 incidents
-6.71 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
646
JULY 2026
642
JUNE 2026
639
MAY 2026
644
Vulnerability
28 May 2026 • TSI
TP-Link: TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
TP-Link Patches High-Severity Vulnerability in TL-WR940N V6 Router
639
CRITICAL-5
TP-1785774351
TP-Link Patches High-Severity Vulnerability in TL-WR940N V6 Router
TP-Link has released a security advisory addressing a high-severity vulnerability (CVE-2026-12935) in its TL-WR940N V6 wireless router. The flaw, rated 8.7 on the CVSS v4.0 scale, could allow unauthenticated attackers to trigger a denial-of-service (DoS) condition or execute remote code under specific conditions.
The vulnerability stems from a stack-based buffer overflow in the router’s RTSP (Real-Time Streaming Protocol) connection tracking module, which processes network traffic within the device’s kernel. Exploitation requires a local network client to connect to a malicious RTSP server, which then sends crafted data to corrupt memory in the router. Successful attacks could crash the device or enable arbitrary code execution, granting attackers control over network settings, traffic interception, DNS manipulation, or further compromise of connected devices.
The flaw affects only the TL-WR940N V6 hardware version, with regional firmware updates now available:
- English models: (EN)_V6_260528
- US models: (US)_V6_260528
- Japanese models: (JP)_V6_260527
Users are advised to verify their router’s hardware version and regional firmware before applying updates, as incorrect installations may cause malfunctions. TP-Link credited Ryo Shimada of Powder Keg Technologies for the responsible disclosure. Until patches are applied, mitigations include restricting outbound RTSP connections and monitoring for suspicious activity, such as unexpected reboots or configuration changes.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MAY 2026
648
Vulnerability
20 May 2026 • TSI
TP-Link: Multiple TP-Link Cameras Vulnerability Allows Hackers to Launch MitM Attacks
TP-Link Patches High-Severity Vulnerabilities in Kasa Smart Cameras
643
CRITICAL-5
TP-1784276626
TP-Link Patches High-Severity Vulnerabilities in Kasa Smart Cameras
TP-Link has released security updates for two vulnerabilities in its Kasa EC70 v4 and EC71 v4 smart cameras, which could allow attackers on the same local network to access sensitive data.
The most critical flaw, CVE-2026-9770 (CVSS 8.6), involves a hardcoded cryptographic key embedded in the camera’s firmware. Exploitation could enable man-in-the-middle (MitM) attacks, allowing threat actors to intercept communications, steal administrative credentials, or manipulate traffic. Attackers could leverage this on shared Wi-Fi networks, compromised routers, or poorly segmented office networks.
The second vulnerability, CVE-2026-13230 (CVSS 5.3), affects the cameras’ local discovery mechanism, exposing geolocation-related data without authentication. While this flaw only impacts confidentiality, it could still aid attackers in reconnaissance.
Both issues have been patched in firmware versions 2.4.0 Build 20260520 and 2.4.1 Build 20260621. TP-Link advises users to update via the Kasa app or official support portal and recommends network segmentation to mitigate risks until patches are applied. Unpatched devices remain vulnerable to exploitation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
650
Vulnerability
20 Apr 2026 • TSI
TP-Link: Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware
Nexcorium Botnet Exploits Unpatched TBK DVRs and TP-Link Routers in Large-Scale DDoS Campaign
645
CRITICAL-5
TP-1776673453
Nexcorium Botnet Exploits Unpatched TBK DVRs and TP-Link Routers in Large-Scale DDoS Campaign
A newly uncovered botnet campaign is exploiting a critical vulnerability in TBK digital video recorders (DVRs) to deploy Nexcorium, a Mirai-based malware designed for large-scale distributed denial-of-service (DDoS) attacks. The flaw, CVE-2024-3721 (CVSS 6.3), affects TBK’s DVR-4104 and DVR-4216 models, which remain widely deployed in small businesses, retail outlets, and surveillance systems due to outdated firmware and weak default credentials.
Attackers exploit the vulnerability by sending a crafted HTTP request to the endpoint `/device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___`, enabling unauthenticated remote code execution (RCE). Once compromised, the device is enslaved into the botnet, with Nexcorium displaying the message “nexuscorp has taken control” upon execution a deliberate signature left by the threat actors.
Researchers at Fortinet’s FortiGuard Labs analyzed the campaign, confirming Nexcorium’s Mirai lineage, including an XOR-encoded configuration table, a watchdog module for persistence, and a DDoS attack module capable of flooding targets on command. The malware also targets end-of-life TP-Link Wi-Fi routers via CVE-2017-17215, expanding its reach by exploiting unpatched legacy hardware.
Nexcorium employs multiple persistence mechanisms, including self-replicating binaries, C2 (command-and-control) communication channels, and Telnet brute-force attacks to propagate across networks. It supports multiple CPU architectures, allowing it to infect a broader range of IoT devices. A watchdog process ensures the malware restarts if terminated, while FNV-1a hashing verifies binary integrity, restoring itself if altered.
The botnet’s dual-target strategy leveraging both TBK DVRs and TP-Link routers creates a geographically distributed attack infrastructure capable of generating massive, hard-to-block DDoS traffic. Since compromised devices operate behind real IP addresses, their traffic appears legitimate, complicating mitigation efforts.
With no patch available for CVE-2024-3721, security researchers recommend replacing affected TBK DVRs and vulnerable TP-Link routers. Network segmentation and disabling unnecessary remote access to DVR management interfaces are also advised to limit exposure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
APRIL 2026
654
Vulnerability
16 Apr 2026 • TSI
TP-Link: TP-Link Router Vulnerability Enables Arbitrary Command Execution
High-Severity Command Injection Flaw Disclosed in TP-Link Routers
650
CRITICAL-4
TP-1780381426
High-Severity Command Injection Flaw Disclosed in TP-Link Routers
A critical authenticated command injection vulnerability, tracked as CVE-2026-5509 (CVSS v4.0: 8.5), has been identified in two TP-Link router models the Archer BE450 v1 and Archer BE7200 v1. The flaw allows attackers to execute arbitrary OS commands via the web management interface after gaining admin access, due to insufficient input sanitization in the backend.
Exploitation requires network adjacency and high privileges but involves low complexity and no user interaction. Successful attacks could grant full device control, enabling threat actors to intercept network traffic, modify system configurations, or deploy unauthorized services posing significant risks to data privacy.
The vulnerability mirrors past TP-Link router flaws, including CVE-2025-14756 (Archer MR600) and CVE-2023-1389 (Archer AX21), highlighting a recurring pattern of command injection risks in the Archer product line.
Affected Models & Remediation
The flaw impacts Archer BE450 v1 and BE7200 v1 running firmware versions earlier than 1.3.0 Build 20260416. TP-Link has released a patch, and users are advised to upgrade immediately. Notably, these models are not sold in the U.S., with distribution primarily in markets like Japan.
While patching is the primary mitigation, administrators should also enforce strong credentials, restrict web management access, and disable remote management unless necessary. Given TP-Link’s history of similar vulnerabilities, regular firmware audits are recommended for ongoing security.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
658
Vulnerability
07 Apr 2026 • TSI
TP-Link: Russian APT28 Hackers Hijack Routers to Steal Credentials
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign
654
CRITICAL-4
TP-1775579951
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign
The UK’s National Cyber Security Centre (NCSC) has issued a warning about two ongoing cyberespionage campaigns by the Russian hacking group APT28 (also known as Fancy Bear, Forest Blizzard, and Sofacy), which is linked to Russia’s GRU military intelligence unit. Since early 2024, APT28 has been hijacking vulnerable internet routers particularly TP-Link models to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations.
### How the Attack Works
APT28 has repurposed virtual private servers (VPS) as malicious DNS servers, intercepting high volumes of DNS requests from compromised routers. The group employs an opportunistic approach, initially casting a wide net to identify potential victims before narrowing down targets of intelligence value.
In one campaign, APT28 exploited CVE-2023-50224, a vulnerability in TP-Link WR841N routers that allows unauthenticated attackers to extract credentials via crafted HTTP requests. By altering the DHCP DNS settings on these routers, the group forced downstream devices (such as laptops and phones) to resolve requests through their malicious servers. This enabled adversary-in-the-middle (AitM) attacks, allowing APT28 to harvest passwords, OAuth tokens, and other credentials from web and email services.
Microsoft Threat Intelligence further reported that APT28 and its sub-group Storm-2754 have been compromising SOHO routers since at least August 2023, expanding their infrastructure to facilitate these attacks.
### Impact and Attribution
The NCSC assesses that APT28’s operations are highly targeted, focusing on entities of strategic interest to Russian intelligence. While the initial router compromises appear broad, the group refines its focus at later stages to prioritize high-value victims. The stolen credentials could enable further unauthorized access, though the exact scope of follow-on attacks remains unclear.
This campaign underscores the persistent threat posed by state-backed cyber actors leveraging common vulnerabilities in consumer-grade networking devices to conduct large-scale espionage.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
663
Vulnerability
28 Mar 2026 • TSI
Microsoft, Splunk, Fortinet, TP-Link, Dell and AWS: Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories
Cybersecurity Roundup: Zero-Days, AI Threats, and Massive Exploits Dominate July 2026
658
CRITICAL-5
DELMICAMAFORSPLTP-1784478360
Cybersecurity Roundup: Zero-Days, AI Threats, and Massive Exploits Dominate July 2026
This week’s cybersecurity landscape underscored the relentless expansion of attack surfaces, with high-impact vulnerabilities, active exploits, and emerging threats targeting everything from enterprise identity systems to AI-driven workflows.
Microsoft’s Patch Tuesday Highlights Critical Exploits
Microsoft’s July 2026 Patch Tuesday addressed 570 vulnerabilities, including two actively exploited zero-days:
- CVE-2026-56164 (SharePoint Server): Allows remote code execution (RCE) via crafted requests.
- CVE-2026-56155 (Active Directory Federation Services): Enables privilege escalation, posing risks to enterprise identity infrastructure.
A BitLocker bypass bug (publicly disclosed) and a Windows User Profile Service exploit (LegacyHive PoC) further exposed post-patch risks, allowing standard users to hijack registry hives.
WordPress Under Siege: 500M Sites at Risk
A pre-authentication RCE flaw (wp2shell, CVE-2026-60137/CVE-2026-63030) in WordPress’s REST API batch-route functionality threatens over 500 million sites, enabling unauthenticated takeovers via SQL injection. The vulnerability remains unpatched for many deployments.
Big Four Breach: EY Confirms Client Data Exposure
Ernst & Young disclosed a breach between March 28 and April 12, 2026, where an unauthorized third party accessed its IT support ticket platform, exfiltrating client tax and investment documents. Detection lagged nearly three weeks, raising concerns about incident response in professional services firms.
AI Systems Emerge as New Attack Vectors
Adversaries are increasingly targeting AI integrations:
- Claude for Chrome: A flaw in the browser extension exposed users to potential data theft.
- GhostCommit: A novel technique hides malicious AI prompts within code commits, manipulating coding assistants undetected.
- GPT-5/6 Exploit Chain: Researchers demonstrated an attack pairing AI models ("Sol") with Chrome vulnerabilities, signaling a shift toward AI-assisted cyberattacks.
Malicious Extensions and Supply Chain Risks
- ModHeader: A popular Chrome/Edge extension (1.6M installs) was removed after dormant code was found exfiltrating browsing history to an external server.
- 7-Zip: A critical flaw enables code execution via crafted archives, impacting widespread file-handling workflows.
- Notepad++ v8.9.7: Patched multiple high-risk bugs, including PowerShell command injection and Zip Slip path traversal.
Enterprise and Cloud Threats Persist
- Dell: Two separate issues emerged BIOS firmware flaws exposing admin passwords and a July 2026 update causing unexpected laptop shutdowns.
- Fortinet/F5/Splunk: Vendors released patches for 10+ vulnerabilities, including Nginx-related flaws (F5) and data-integrity risks (Splunk).
- AWS Cost Explorer: A bug introduced security and data-exposure risks for cloud billing monitoring.
- TP-Link Cameras: A flaw could allow attackers to compromise device functionality or access video feeds.
The week’s disclosures reflect a broadening threat landscape, where legacy systems, AI tools, and third-party integrations remain prime targets for exploitation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
678
Cyber Attack
01 Feb 2026 • TSI
Ruijie, TP-Link and Hadoop: RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
RustDuck: A Stealthy, Rust-Based Botnet Targeting Routers and Servers
659
HIGH-19
RUITP-HOR1782865482
RustDuck: A Stealthy, Rust-Based Botnet Targeting Routers and Servers
Researchers at QiAnXin’s XLab have uncovered RustDuck, a two-stage malware family actively hijacking home routers, IP cameras, Android devices, and poorly secured servers to build a distributed denial-of-service (DDoS) botnet. First tracked in February 2026, RustDuck stands out not for its current scale but for its rapid evolution and sophisticated evasion tactics.
### Infection Vectors
RustDuck spreads through multiple well-known vulnerabilities, exploiting:
- Default or weak credentials on Telnet and SSH services.
- Unpatched flaws in devices from TVT (DVRs/cameras), Ruijie, TP-Link, ZTE, and Android debugging interfaces.
- Vulnerable web software, including ThinkPHP, Jenkins, and Hadoop YARN.
Over 20 IP addresses have been identified as distribution points, with the most active 176.65.139[.]204 sharing address space with a separate ADB-targeting botnet reported earlier in 2026.
### Evasion and Stealth
RustDuck’s design prioritizes evasion, employing a two-stage infection process:
1. A lightweight loader decrypts and deploys a core module, increasingly rewritten in Rust a language that complicates reverse engineering compared to traditional C-based malware.
2. The core module performs extensive anti-analysis checks, including:
- Detecting debuggers (e.g., Wireshark, gdb), virtual machines, and honeypots.
- Testing for reserved IP responses to identify fake networks.
- Comparing system clocks to detect sandbox time acceleration.
Communication is encrypted using ChaCha20-Poly1305 and AES-GCM, with keys rotated every 10 minutes. Traffic mimics legitimate HTTPS to avoid detection. Command-and-control (C2) servers leverage dynamic DNS services like duckdns.org, allowing operators to issue DDoS commands, update malware, or switch C2 addresses.
### Broader Context
RustDuck follows a growing trend of Rust-based botnets, such as RustoBot (documented in April 2025), which targeted routers for DDoS attacks. While smaller than record-breaking botnets like AISURU (3M+ devices, 30 Tbps attacks), RustDuck’s advanced techniques Rust rewrites and anti-analysis measures signal a shift toward more resilient malware.
The botnet’s infrastructure overlaps with other DDoS operations, suggesting possible shared hosting or coordinated activity. Though currently limited in scale, its development pace and evasion methods could inspire future threats.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2026
678
DECEMBER 2025
675
NOVEMBER 2025
675
OCTOBER 2025
673
SEPTEMBER 2025
671
AUGUST 2025
687
Cyber Attack
01 Aug 2025 • TSI
TP-Link: US operation evicts Russia from hacked SOHO routers used to breach critical infrastructure
U.S. Disrupts Russian GRU’s Global Router Hijacking Campaign Targeting Governments and Critical Infrastructure
667
CRITICAL-20
TP-1775665616
U.S. Disrupts Russian GRU’s Global Router Hijacking Campaign Targeting Governments and Critical Infrastructure
The U.S. Department of Justice (DOJ) announced on Tuesday that it had dismantled a years-long cyberespionage operation by Russia’s military intelligence agency, the GRU, which had hijacked thousands of small office and home office (SOHO) routers worldwide to intercept sensitive data. The campaign, active since at least 2024 (with evidence dating back to August 2025), exploited TP-Link routers to reroute DNS requests through Kremlin-controlled servers, enabling the theft of emails, passwords, and other confidential information from governments, critical infrastructure operators, and private networks.
The FBI’s "Operation Masquerade" neutralized the threat by remotely resetting compromised routers and collecting forensic evidence, effectively severing Russia’s access. The operation followed a Microsoft report revealing that the GRU’s hacking group tracked as APT28, Fancy Bear, or Forest Blizzard had weaponized DNS hijacking to conduct adversary-in-the-middle (AiTM) attacks, particularly targeting Microsoft Outlook connections. An automated filtering system allowed the hackers to prioritize high-value targets, including three African government organizations, as well as entities in IT, telecommunications, and energy sectors.
Microsoft warned that the scale of compromised routers could amplify future AiTM attacks, though no malware delivery or denial-of-service activity has been observed yet. The GRU’s tactics reflect an evolution in its playbook, marking the first time the group has used DNS hijacking at scale to exploit edge devices for large-scale surveillance.
The disruption aligns with the FBI’s broader strategy to proactively counter state-sponsored cyber threats. Brett Leatherman, head of the FBI’s Cyber Division, emphasized the agency’s commitment to imposing costs on foreign adversaries targeting U.S. interests. The UK’s National Cyber Security Centre (NCSC) also issued an advisory on the campaign, underscoring the risks of unpatched or end-of-life networking equipment.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2025
739
Breach
01 Feb 2025 • TSI
TP-Link USA
TP-Link Potential Ban Due to Security Concerns
677
HIGH-62
TP-000022225
TP-Link, a prominent US router manufacturer with historical ties to China, faces a potential ban due to security concerns and ongoing investigations. Accusations revolve around the possibility of Chinese state-sponsored hackers compromising routers, and the company's obligation under Chinese law to provide sensitive information. This controversy has raised questions about TP-Link’s prices and market dominance, with fears that it might reflect a strategy to unfairly influence the US market. The company rebukes these concerns, highlighting its restructuring efforts, diverse manufacturing locations, and transparency with US investigators.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
NOVEMBER 2024
757
Cyber Attack
01 Nov 2024 • TSI
NETGEAR, Huawei, TP-Link and D-Link: Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach
737
LOW-20
HUADLITP-NET1775672907
Masjesu Botnet: A Stealthy DDoS-for-Hire Threat Expands Its Reach
Cybersecurity researchers have uncovered Masjesu, a sophisticated botnet operating as a DDoS-for-hire service since 2023. Marketed via Telegram under the alias XorBot, the malware targets IoT devices including routers, cameras, and gateways across multiple architectures, employing XOR-based encryption to evade detection.
First documented by Chinese security firm NSFOCUS in December 2023 and linked to an operator known as synmaestro, Masjesu has since evolved. A 2024 update introduced 12 new exploits targeting devices from D-Link, Huawei, NETGEAR, TP-Link, and others, alongside enhanced DDoS flood modules. Researchers note its rapid growth, with attackers increasingly leveraging Telegram for recruitment and promotion.
Trellix’s recent analysis reveals Masjesu’s focus on volumetric DDoS attacks, particularly against CDNs, game servers, and enterprises. The botnet’s infrastructure is heavily concentrated in Vietnam (nearly 50% of observed traffic), with additional activity in Ukraine, Iran, Brazil, Kenya, and India. Once deployed, the malware establishes persistence, disables competing processes, and connects to command servers to execute attacks.
Masjesu also self-propagates by scanning for vulnerable devices, including Realtek routers via port 52869 a tactic previously used by botnets like JenX and Satori. Notably, the botnet avoids high-profile targets like the U.S. Department of Defense to minimize legal scrutiny, prioritizing long-term survival over mass infection.
As IoT exploitation expands, Masjesu’s low-visibility approach and social media-driven recruitment underscore its adaptability as a persistent cyber threat.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for TSI ??
What was TSI's A.I Rankiteo Cyber Score in July 2026 ??
What was TSI's A.I Rankiteo Cyber Score in June 2026 ??
What was TSI's A.I Rankiteo Cyber Score in May 2026 ??
What was TSI's A.I Rankiteo Cyber Score in April 2026 ??
What was TSI's A.I Rankiteo Cyber Score in March 2026 ??
What was TSI's A.I Rankiteo Cyber Score in February 2026 ??
What was TSI's A.I Rankiteo Cyber Score in January 2026 ??
What was TSI's A.I Rankiteo Cyber Score in December 2025 ??
What was TSI's A.I Rankiteo Cyber Score in November 2025 ??
What was TSI's A.I Rankiteo Cyber Score in October 2025 ??
What was TSI's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on TSI's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with TSI ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view TSI's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?