New CVEs
New vulnerabilities worth mentioning for the ISPs:
CPE/APs – botnet fuel🔥
CVE-2025-13942 (Zyxel CPE / ONT / 5G routery)
-
Podmínka: WAN + UPnP enabled
-
~120k exposed devices
-
ideální pro: botnety (Mirai-style), DDoS amplification, často v managed CPE flotilách
CVE-2025-7850 / 7851 (TP-Link VPN / routers)
-
root RCE
-
vector: WireGuard config + leftover debug code
-
persistence i po patchích
Hosting, CDN, Linux
CVE-2026-31431 – Linux Kernel (“Copy Fail”)
-
Lokální eskalace práv na root.
-
Funkční exploity jsou veřejně dostupné.
CVE-2026-33032 (nginx-ui)
-
full server takeover
-
Bacha na často “exposed” admin UI