In a June 7, 2022 advisory, the NSA, CISA, and FBI said Chinese state-sponsored actors had compromised telecommunications companies and other network providers, primarily by exploiting publicly known vulnerabilities. The agencies said the activity had used specific techniques and common vulnerabilities since 2020. Later advisories broadened the picture: a 2024 guide addressed a global telecom espionage campaign, and a CISA advisory revised in 2025 described further activity and examples of exploited flaws.
What the 2022 advisory said
The joint advisory, “People’s Republic of China State-Sponsored Cyber Actors Exploit Network Providers and Devices”, described PRC state-sponsored actors targeting and compromising major telecommunications companies and network service providers. The NSA’s June 7, 2022 announcement says the actors primarily used publicly known vulnerabilities and that exploitation of specific techniques and common vulnerabilities had occurred since 2020.
The point is not that every intrusion relied on a new, previously unknown flaw. The agencies emphasized known weaknesses in network devices and providers’ infrastructure. The NSA announcement does not enumerate CVEs in its summary, so specific vulnerabilities should not be attributed to the 2022 advisory without checking its full technical document.
How later advisories expanded the picture
December 2024: guidance for communications infrastructure
On December 4, 2024, CISA, NSA, the FBI, Australia’s ACSC, Canada’s CCCS, and New Zealand’s NCSC published “Enhanced Visibility and Hardening Guidance for Communications Infrastructure.” The agencies described a broad, significant PRC-affiliated cyber espionage campaign involving major global telecommunications providers. The guide is aimed at network engineers and defenders, and its advice can also apply to organizations operating on-premises enterprise equipment.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Network Security, Firewalls, and VPNs | $66.62 | Buy on Amazon |
| 2 |
|
Network Security, Firewalls, and VPNs: . (Issa) | $62.45 | Buy on Amazon |
| 3 |
|
TP-Link ER605, Wired Gigabit VPN Router | $44.99 | Buy on Amazon |
| 4 |
|
Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid | $33.89 | Buy on Amazon |
September 2025: broader network activity and CVE examples
CISA’s AA25-239A advisory, last revised September 3, 2025, covers Chinese state-sponsored compromise of networks worldwide to support a global espionage system. It discusses targeting in telecommunications and other sectors, commonly exploited public vulnerabilities, and avoidable weaknesses in exposed network-edge devices. CISA says the initial-access vectors remain an information gap in the activity it describes.
The advisory lists examples of exploited vulnerabilities, including:
- CVE-2024-21887: Ivanti Connect Secure and Ivanti Policy Secure.
- CVE-2024-3400: Palo Alto Networks PAN-OS GlobalProtect under specified configurations.
- CVE-2023-20273 and CVE-2023-20198: Cisco IOS XE.
- CVE-2018-0171: Cisco IOS and IOS XE.
These are examples cited by the 2025 advisory, not an exhaustive list and not proof that every listed vulnerability was used against a telecommunications target.
#1 Best Overall
Were the attacks based on zero-days?
In the activity covered by AA25-239A, CISA said investigators had not observed exploitation of zero-day vulnerabilities to date. That finding is limited to the investigations summarized in that advisory; it does not establish that zero-days were never used in other operations or periods. The agencies’ emphasis in these advisories is that known, patchable vulnerabilities and other avoidable weaknesses can still provide attackers with access.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteHow telecom and network defenders can reduce exposure
The agencies’ recommendations center on reducing reachable weaknesses and improving the ability to detect unauthorized changes or access. The 2022 NSA announcement summarizes several foundational measures:
Rank #2
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
- Apply security patches as soon as possible, prioritizing vulnerabilities according to risk and known exploitation.
- Disable ports and protocols that are not necessary for the network’s operation.
- Replace end-of-life network infrastructure that no longer receives security support.
- Segment networks to limit how far an intrusion can move.
- Enable robust logging for internet-facing services and access to network infrastructure.
CISA’s 2025 advisory further recommends ensuring edge devices are not vulnerable to the listed known-exploited CVEs and regularly reviewing network-device logs and configurations for unexpected, unapproved, or unusual activity. The 2024 hardening guide focuses on improving visibility and hardening communications equipment. It also urges manufacturers to prioritize secure-by-design configurations and customers to demand secure-by-design products.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to interpret the agency timeline
| Date | Document | What it covers |
|---|---|---|
| June 7, 2022 | NSA, CISA, and FBI joint advisory | PRC actors exploiting publicly known vulnerabilities against network providers and devices; the agencies said the activity had used specific techniques and common vulnerabilities since 2020. |
| December 4, 2024 | Multi-agency communications infrastructure guide | Visibility and hardening for defenders amid a broad PRC-affiliated espionage campaign involving major global telecom providers. |
| September 3, 2025 | CISA advisory AA25-239A, last revised on this date | Network compromise activity across telecommunications and other sectors, examples of exploited CVEs, and defensive recommendations. |
The releases are related in subject, but they are not one event or one document. Details about CVEs listed in AA25-239A belong to the later CISA advisory, not automatically to the 2022 joint advisory. CISA also notes partial overlap between the activity it describes and several commercial threat-intelligence labels, including “Salt Typhoon.” Those are industry names; the agencies do not establish one as a definitive official alias.
Quick Recap
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

