TROYANOSYVIRUS
Volver a CVEs

CVE-2025-15608

CRITICAL
9.8

Descripcion

This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/20/2026
Ultima modificacion4/2/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

tp-link:archer_ax53tp-link:archer_ax53_firmware

Debilidades (CWE)

CWE-121

Referencias

https://www.tp-link.com/us/support/faq/5025/(f23511db-6c3e-4e32-a477-6aa17d310630)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.