NVD disclosure day

Published threat advisories for August 29, 2025

CVE advisoryCRITICAL

CVE-2024-46484

TRENDnet TV-IP410 Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical OS command injection vulnerability exists in the TRENDnet TV-IP410 camera. Attackers can exploit this over the network to inject commands, potentially leading to device compromise and control. Organizations should verify if this device is in use and exposed to the network.

CVE advisoryKnown Exploit

CVE-2025-9377

TP-Link Router Command Execution Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An authenticated remote command execution vulnerability impacts specific TP-Link router models. This could allow attackers to gain unauthorized control over affected devices, posing a business risk, especially as the products are end-of-life and no longer supported by the vendor.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-55177

WhatsApp Synchronization Vulnerability Allows Unauthorized Content Processing.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An issue within WhatsApp synchronization messages could allow an unauthorized user to trigger content processing from any URL on a target device. This poses a risk to affected organizations and their employees, as it may enable targeted attacks. The business risk involves potential unauthorized access to user data and

• CISA KEV