← Back to CVEs
CVE-2025-15607
CRITICAL9.8
Description
A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful exploitation may allow execution of malicious commands and ultimately full control of the device.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published3/20/2026
Last Modified4/2/2026
Sourcenvd
Honeypot Sightings0
Affected Products
tp-link:archer_ax53tp-link:archer_ax53_firmware
Weaknesses (CWE)
CWE-77
References
https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware(f23511db-6c3e-4e32-a477-6aa17d310630)
https://www.tp-link.com/us/support/faq/5025/(f23511db-6c3e-4e32-a477-6aa17d310630)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.