CVE-2025-15608

CRITICAL

Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53

Title source: cna

Description

This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.

Scores

CVSS v3 9.8
EPSS 0.0026
EPSS Percentile 48.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-121
Status published
Products (2)
tp-link/archer_ax53_firmware 1.0
TP-Link Systems Inc./AX53 v1 < 251029
Published Mar 20, 2026
Tracked Since Mar 20, 2026