The U.S. CISA has added three critical security flaws affecting AMI MegaRAC, D-Link DIR-859 routers, and Fortinet FortiOS to its KEV catalog due to active exploitation. These vulnerabilities pose serious risks, including remote control, privilege escalation, and data decryption. #AMI MegaRAC #D-Link DIR-859 #Fortinet FortiOS
Keypoints
- Three security flaws have been added to CISAβs KEV catalog with evidence of active exploitation.
- CVE-2024-54085 in AMI MegaRAC allows remote control through an authentication bypass.
- CVE-2024-0769 in D-Link DIR-859 routers enables privilege escalation; the device is unpatched due to end-of-life status.
- CVE-2019-6693 in Fortinet products involves hard-coded cryptographic keys, risking password decryption.
- Federal agencies must implement mitigations by July 16, 2025, to protect against these vulnerabilities.
Read More: https://thehackernews.com/2025/06/cisa-adds-3-flaws-to-kev-catalog.html