<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #TP Link</title><description>Cybersecurity articles tagged #TP Link on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>TP-Link Sued: Router Security Misrepresentation &amp; China Ties</title><link>https://runtimerebel.com/blog/tp-link-sued-router-security-misrepresentation-china-ties</link><guid isPermaLink="true">https://runtimerebel.com/blog/tp-link-sued-router-security-misrepresentation-china-ties</guid><description>Four U.S. states sue TP-Link over allegations of misleading security claims, undisclosed China ties, and privacy risks affecting consumer routers.</description><pubDate>Fri, 09 Oct 2026 14:48:06 GMT</pubDate><category>TP Link</category><category>Router Security</category><category>Supply Chain Risk</category><category>China</category><category>Privacy</category></item><item><title>Evooo1Bot Linux Botnet Turns Routers Into SOCKS5 Relays</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</guid><description>A new Mirai-based modular Linux botnet called Evooo1Bot targets internet routers, turning them into SOCKS5 traffic relay nodes.</description><pubDate>Sat, 15 Aug 2026 16:14:07 GMT</pubDate><category>DDoS</category><category>Credential Theft</category><category>D Link</category><category>TP Link</category><category>Mirai</category></item><item><title>TP-Link Zero-Trust Provisioning Bugs: 15 Flaws Threaten Security</title><link>https://runtimerebel.com/blog/tp-link-zero-trust-provisioning-bugs-15-flaws-threaten-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/tp-link-zero-trust-provisioning-bugs-15-flaws-threaten-security</guid><description>Researchers uncover 15 TP-Link device bugs that undermine automated zero‑trust provisioning, exposing credential leakage and network compromise.</description><pubDate>Mon, 10 Aug 2026 09:10:12 GMT</pubDate><category>TP Link</category><category>Zero Trust</category><category>Provisioning</category><category>Network Devices</category><category>Credential Exposure</category></item><item><title>TP-Link Archer AX21 RCE via CVE-2023-1389 — Mitigation Guide</title><link>https://runtimerebel.com/blog/tp-link-archer-ax21-rce-via-cve-2023-1389-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/tp-link-archer-ax21-rce-via-cve-2023-1389-mitigation-guide</guid><description>Hackers continue targeting discontinued TP-Link Archer AX21 routers with CVE-2023-1389, though many exploitation attempts currently fail to execute payloads.</description><pubDate>Mon, 20 Apr 2026 08:54:58 GMT</pubDate><category>CVE-2023-1389</category><category>TP Link</category><category>Archer AX21</category><category>MooBot</category><category>Mirai</category><category>Command Injection</category></item><item><title>APT28 Exploits MikroTik &amp; TP-Link Routers in DNS Hijacking</title><link>https://runtimerebel.com/blog/apt28-exploits-mikrotik-tp-link-routers-in-dns-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-mikrotik-tp-link-routers-in-dns-hijacking</guid><description>Russian state-linked APT28 (Forest Blizzard) is compromising insecure SOHO routers globally, employing DNS hijacking for cyber espionage since May 2025.</description><pubDate>Tue, 07 Apr 2026 20:18:04 GMT</pubDate><category>APT28</category><category>Forest Blizzard</category><category>SOHO Routers</category><category>MikroTik</category><category>TP Link</category><category>DNS Hijacking</category><category>Cyber Espionage</category></item><item><title>APT28 FrostArmada DNS Hijack Campaign Steals Microsoft 365 Logins</title><link>https://runtimerebel.com/blog/apt28-frostarmada-dns-hijack-campaign-steals-microsoft-365-logins</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-frostarmada-dns-hijack-campaign-steals-microsoft-365-logins</guid><description>Authorities disrupt APT28&apos;s FrostArmada campaign, which used DNS hijacking of MikroTik and TP-Link routers to steal Microsoft 365 account credentials.</description><pubDate>Tue, 07 Apr 2026 16:28:36 GMT</pubDate><category>APT28</category><category>FrostArmada</category><category>DNS Hijacking</category><category>Microsoft 365</category><category>MikroTik</category><category>TP Link</category><category>Credential Theft</category></item><item><title>CVE-2024-5035: TP-Link Archer C5400X RCE Vulnerability Patch</title><link>https://runtimerebel.com/blog/cve-2024-5035-tp-link-archer-c5400x-rce-vulnerability-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-5035-tp-link-archer-c5400x-rce-vulnerability-patch</guid><description>TP-Link fixes high-severity flaws including CVE-2024-5035 and CVE-2024-3922, preventing remote code execution and authentication bypass on gaming routers.</description><pubDate>Fri, 27 Mar 2026 12:25:33 GMT</pubDate><category>CVE-2024-5035</category><category>CVE-2024-3922</category><category>TP Link</category><category>Archer C5400X</category><category>RCE</category><category>Router Security</category></item><item><title>Archer NX200 and NX510v Auth Bypass: CVE-2024-5035 Patch Guidance</title><link>https://runtimerebel.com/blog/archer-nx200-and-nx510v-auth-bypass-cve-2024-5035-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/archer-nx200-and-nx510v-auth-bypass-cve-2024-5035-patch-guidance</guid><description>TP-Link patches critical auth bypass CVE-2024-5035 and command injection in Archer NX routers, preventing unauthorized firmware uploads and remote code execution.</description><pubDate>Wed, 25 Mar 2026 12:23:09 GMT</pubDate><category>CVE-2024-5035</category><category>CVE-2024-5036</category><category>TP Link</category><category>Archer NX200</category><category>Archer NX510v</category><category>Firmware Security</category></item></channel></rss>