GHSA-6mh6-q22w-5c4pHighCVSS 9.8
This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe...
🔗 CVE IDs covered (1)
📋 Description
This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques.
Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2025-15608
- https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware
- https://www.tp-link.com/us/support/faq/5025
- https://www.tp-link.com/en/support/download/archer-ax55/v4
- https://www.tp-link.com/us/support/download/archer-ax55/v4.60/#Firmware
- https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware
- https://github.com/advisories/GHSA-6mh6-q22w-5c4p