Vulnerabilities · 68 days ago

Routers Become Shared Cover for Espionage

UAT-7810 is moving from using compromised routers for its own traffic to operating a reusable relay layer that other China-linked actors can borrow. Once an edge device is folded into that network, source IP, geolocation, and simple proxy blocking stop telling defenders who is really behind the intrusion.

Cisco Talos says the group is refining LONGLEASH and adding DOGLEASH, JARLEASH, and LeashTest to expand LapDogs across more hardware, including MIPS, ARM, and x64 systems. Talos links the activity to unpatched Ruckus router flaws CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, and ASUS AiCloud CVE-2025-2492, and says UAT-7810 is providing relay infrastructure that UAT-5918 has already used against critical infrastructure targets.

The forward risk is shared infrastructure. Cleaning one router or blocking one relay does not remove the service layer if the device is still being used as a reusable ORB node for later espionage.

CVE-2023-25717

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as… EPSS 98% (100th percentile).

CISA federal remediation date Jun 2 · date passed

CVE-2025-2492

NVD KEV

EPSS 1% (64th percentile).

CVE-2020-22653

NVD KEV

CVSS 9.8 CRITICAL: in Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus… EPSS 0.6% (44th percentile).

CVE-2020-22658

NVD KEV

CVSS 9.8 CRITICAL: in Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus… EPSS 0.5% (41st percentile).

Timeline

Sources

5 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-09

Editions

Related stories