TROYANOSYVIRUS
Back to CVEs

CVE-2025-15607

CRITICAL
9.8

Description

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful exploitation may allow execution of malicious commands and ultimately full control of the device.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published3/20/2026
Last Modified4/2/2026
Sourcenvd
Honeypot Sightings0

Affected Products

tp-link:archer_ax53tp-link:archer_ax53_firmware

Weaknesses (CWE)

CWE-77

References

https://www.tp-link.com/us/support/faq/5025/(f23511db-6c3e-4e32-a477-6aa17d310630)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.