New CVEs

New vulnerabilities worth mentioning for the ISPs:

CPE/APs  – botnet fuel🔥

CVE-2025-13942 (Zyxel CPE / ONT / 5G routery)

  • Podmínka: WAN + UPnP enabled

  • ~120k exposed devices

  • ideální pro: botnety (Mirai-style), DDoS amplification, často v managed CPE flotilách

CVE-2025-7850 / 7851 (TP-Link VPN / routers)

  • root RCE

  • vector: WireGuard config + leftover debug code

  • persistence i po patchích

Hosting, CDN, Linux

CVE-2026-31431 – Linux Kernel (“Copy Fail”)

  • Lokální eskalace práv na root.

  • Funkční exploity jsou veřejně dostupné.

CVE-2026-33032 (nginx-ui)

  • full server takeover

  • Bacha na často “exposed” admin UI

Flooding from Bulgaria

For the past days/weeks many ISP around europe are targeted by SYN flood originating from ASs mainly from Bulgaria. Although we love the country, we recommend to filter out traffic from following ASNs:

  • ASN52055
  • ASN34224

Note FLOWCUTTER is not an BGP / routing authority and cannot be held responsible for inconveniences resulted from recommendations made.