{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-15608",
"assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"state": "PUBLISHED",
"assignerShortName": "TPLink",
"dateReserved": "2026-03-10T17:11:18.919Z",
"datePublished": "2026-03-20T16:31:38.921Z",
"dateUpdated": "2026-08-12T18:56:15.429Z"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
"shortName": "TPLink",
"dateUpdated": "2026-08-12T18:56:15.429Z"
},
"title": "Buffer Overflow in Network Probe Handling Function of TP-Link Archer AX53 + Archer AX55",
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"cweId": "CWE-121",
"description": "CWE-121 Stack-based buffer overflow",
"type": "CWE"
}
]
}
],
"impacts": [
{
"capecId": "CAPEC-100",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-100 Overflow Buffers"
}
]
}
],
"affected": [
{
"vendor": "TP-Link Systems Inc.",
"product": "AX53 v1",
"modules": [
"tdpServer"
],
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "251029",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "AX55 v4",
"modules": [
"tdpServer"
],
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "(US)_1.2.1 Build 20260527",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "AX55 v4.6",
"modules": [
"tdpServer"
],
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "(US)_1.2.1 Build 20260527",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
],
"descriptions": [
{
"lang": "en",
"value": "This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. \n\nSuccessful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. \n
Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.
"
}
]
}
],
"references": [
{
"url": "https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware",
"tags": [
"patch"
]
},
{
"url": "https://www.tp-link.com/us/support/faq/5025/",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware",
"tags": [
"patch"
]
},
{
"url": "https://www.tp-link.com/us/support/download/archer-ax55/v4.60/#Firmware",
"tags": [
"patch"
]
},
{
"url": "https://www.tp-link.com/en/support/download/archer-ax55/v4/",
"tags": [
"patch"
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV4_0": {
"attackVector": "ADJACENT",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"vulnConfidentialityImpact": "HIGH",
"subConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"subIntegrityImpact": "LOW",
"vulnAvailabilityImpact": "HIGH",
"subAvailabilityImpact": "LOW",
"exploitMaturity": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"valueDensity": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"version": "4.0",
"baseSeverity": "HIGH",
"baseScore": 7.7,
"vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L"
}
}
],
"credits": [
{
"lang": "en",
"value": "samuzora",
"type": "finder"
},
{
"lang": "en",
"value": "Voidchunk",
"type": "finder"
},
{
"lang": "en",
"value": "WeiYao Luo",
"type": "finder"
}
],
"source": {
"discovery": "UNKNOWN"
},
"x_generator": {
"engine": "Vulnogram 1.0.0"
}
},
"adp": [
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"timestamp": "2026-03-21T04:01:44.173518Z",
"id": "CVE-2025-15608",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"version": "2.0.3"
}
}
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-03-23T13:01:23.572Z"
}
}
]
}
}