Hanoi Police warn of cybersecurity risks from old City- Linkcast devices

Minh Hạnh |

Hanoi City Police discovered a number of serious security vulnerabilities that could affect agencies and organizations in Vietnam.

The Department of Cyber Security and High-Tech Crime Prevention (Hanoi City Police) warns about security vulnerabilities of old CVE and Router City- Link devices that could impact the systems of domestic agencies and organizations. Specifically as follows:

1. Software security vulnerability on email service

CVE-2025-59689 District Command filling vulnerability in Libraesva Email Security Gateway

CVSS score: 6.1/10 Level: Average (Medium).

described: hackers can exploit vulnerabilities by entering enabled commands via email with specially designed compressed attachments, allowing them to execute arbitrary commands as unprivileged users. The reason is that the file scanning process did not handle it properly when Deleting the executable code from some compression storage formats.

Affected version: Libraesva ESG from version 4.5 to before 5.0.31.

Recommendation: Libraesva has released an emergency, automatic patch for all customers using ESG 5.x (no additional operations required).For users of version 4.x, it is necessary to manual update according to the instructions at: https://docs.libraesva.com/document/migration/libraesva-esg-4-x-to-5-x-migration-guide


PoC review: There is currently no public exploitation code (PoC).

2. Software security vulnerability in the browser

CVE-2025-11152 nguyen tac of the whole number of flows causing sandbox exits on Firefox CVSS score: 8.6/10 Level: High (High).

described: nguyen tac of the Graphics components: Canvas2D can allowhaters to exit the Sandbox, access sensitive data from memory, or execute malware.

Affected version: Firefox 143.0.3 or later.

Recommendation: Mozilla has fixed it in version 143.0.3.Users should upgrade to this version or later to minimize risks.The fix has also been integrated into Linux distributions such as Ubuntu and Debian.For details, see: https://www.mozilla.org/en-US/security/advisories/mfsa2025 80


3. vulnerabilities on old Router TP- Link devices

Many old TP- Link Router models in use at agencies and units have stopped supporting firmware updates or stopped providing services ( End-of-Life/ End-of- Service) such as: TP- Link TL-WR740N, TL-WR841N, TL-WR940N, Archer C50, Archer C20, TL-WR1043ND, TL-MR3420...


These devices have many serious vulnerabilities and will never be patched, becoming a popular attack target.

Common errors include: Commandmand Injection Buffer Overflow Authentication Bypass remote code execution (RCE).

hackers can: Exploit remote remote control; steal login information and network data; redirect users to phishing sites; Create Botnet for DDoS attacks; Spread malware in internal networks.

Proposed remediation

For Router TP- Link devices that have stopped support, the patching cannot be done through software updates but requires more drastic measures:

Review and count the device: Make a list of all routers in use in the agency, unit; Clearly record the model, firmware version.

Look up the support status: Check on the official website of TP- Link to determine the EoL/EoS status.

Replace the device: It is mandatory to replace the old router with a new device that supports regular security updates.

Strengthening network security: Network Segmentation: Issuing an important system to limit spread.

Firewall: Tight setup, only allowing necessary connections.

Infrastructure detection/prevention system (IDS/IPS): Traffic monitoring and warning of unusual behavior.

The Department of Cyber Security and High-Tech Crime Prevention, Hanoi City Police recommends that agencies, businesses, organizations and individuals seriously implement the above instructions to promptly detect, overcome risks and prevent cyber attacks, ensure information security in the system.

Minh Hạnh
RELATED NEWS

In which cases are People's Public Security inspectors dismissed

|

The dismissal of People's Public Security inspectors is divided into two groups: of course dismissal and dismissal according to the decision of the Minister of Public Security.

The Ministry of Construction guides freelance workers to come to the commune police to confirm their income from buying social housing

|

On the Ministry of Construction's Information Portal on November 10, the Ministry of Construction responded to instructions for freelance workers to go to the commune police to confirm their income to buy social housing.

People can officially submit red books on VNeID, no need to submit photo cards to the People's Committee of the commune and ward

|

From today, people can submit red books on VNeID to State agencies to clean up land data, instead of submitting photocopies directly as before.

Apartment fire on the 16th floor of an apartment building in Ho Chi Minh City

|

HCMC - A fire broke out in an apartment on the 16th floor of an apartment building in Phuoc Long Ward, fortunately there were no casualties.

Hundreds of thousands of Ukrainian refugees in the US have their food subsidies suspended

|

Washington has just issued a decision to remove Ukrainian refugees living in the US from the food subsidy program, part of Trump's budget cutting efforts.

Domestic gold prices increase, people line up to buy

|

Although domestic gold prices have continuously increased, many people are still flocking to gold shops lining up to buy.

Many businesses live well thanks to bank deposit interest

|

The large cash flow of idle money helps many businesses earn thousands of billions of VND from bank deposit interest and bond investment, contributing significantly to profits.

Teachers in the mountainous areas of Da Nang cross landslides to bring students to class

|

Da Nang - In the midst of hardship, teachers in mountainous areas still persistently cross mountains, take students to class, and keep their book journey uninterrupted during the landslide season.

In which cases are People's Public Security inspectors dismissed

Trà My |

The dismissal of People's Public Security inspectors is divided into two groups: of course dismissal and dismissal according to the decision of the Minister of Public Security.

The Ministry of Construction guides freelance workers to come to the commune police to confirm their income from buying social housing

Xuyên Đông |

On the Ministry of Construction's Information Portal on November 10, the Ministry of Construction responded to instructions for freelance workers to go to the commune police to confirm their income to buy social housing.

Công an Hà Nội truy nã đối tượng giả danh cán bộ Bộ Quốc phòng để lừa đảo

SÓNG HỮU |

Hà Nội - Kiếm sống bằng nghề môi giới mua bán nhà đất, Mí nói dối mình là cán bộ của Bộ Quốc phòng để dụ dỗ nạn nhân thuê đất rồi chiếm đoạt tài sản.