CVE-2025-15608

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:archer_ax53_firmware:1.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_ax53:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-20 17:16

Updated : 2026-08-12 20:17


NVD link : CVE-2025-15608

Mitre link : CVE-2025-15608

CVE.ORG link : CVE-2025-15608


JSON object : View

Products Affected

tp-link

  • archer_ax53_firmware
  • archer_ax53
CWE
CWE-121

Stack-based Buffer Overflow