Cisco Talos Discloses Vulnerabilities in TP-Link, Canva, and HikVision Devices

Summary: Cisco Talos researchers disclosed multiple security vulnerabilities affecting TP-Link routers, Canva design tools, and HikVision surveillance terminals, requiring immediate vendor patching.

Cisco Talos researchers have disclosed a series of security vulnerabilities affecting enterprise and consumer devices. The findings were shared with respective vendors, who have since issued patches in accordance with third-party disclosure policies. These issues span design tools, networking hardware, and surveillance equipment.

Researchers identified nineteen distinct flaws within Canva Affinity, a graphic design utility. Eighteen involve out-of-bounds reads in the EMF functionality, which could expose sensitive information via crafted files. One additional type confusion flaw allows for arbitrary code execution through memory corruption.

Ten vulnerabilities were discovered in TP-Link Archer AX53 routers. These include multiple buffer overflows in the SSH server opcode and a misconfiguration risking credential leaks during man-in-the-middle attacks. Network packets are required to trigger the conditions.

A single stack-based buffer overflow was found in HikVision terminals. This flaw impacts the SADP XML parsing functionality on Ultra Face Recognition Terminals. Exploitation could lead to remote code execution.

Organizations should verify patch status on affected inventory lists. Cisco Talos provides rule sets for Snort detection, and advisories are available on the vendor website for monitoring exploitation attempts.

Key facts

  • 19 vulnerabilities in Canva Affinity
  • 10 vulnerabilities in TP-Link Archer AX53
  • 1 vulnerability in HikVision Ultra Face Recognition Terminal
  • TALOS-2025-2290, CVE-2025-62673
  • TALOS-2025-2281, CVE-2025-66176

Why it matters

Patching is critical to prevent remote code execution or credential leaks in widely deployed devices. Attackers may leverage these flaws to access networks via compromised hardware or software.

Key metrics

  • Total Vulnerabilities Disclosed: 30 vulnerabilities (Combined count across Canva, TP-Link, and HikVision products)