CVE-2025-15608

Summary

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques.

Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.AX53 v10 < 251029affected
TP-Link Systems Inc.AX55 v40 < (US)_1.2.1 Build 20260527affected
TP-Link Systems Inc.AX55 v4.60 < (US)_1.2.1 Build 20260527affected

Weaknesses

  • CWE-121: CWE-121 Stack-based buffer overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References