# CVE-2025-15608

## Summary

- **CVE ID:** CVE-2025-15608
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)
- **CWE:** CWE-121
- **Published:** Mar 20, 2026
- **Last Modified:** Aug 12, 2026

## Description

This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques.  

Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.

## Affected Products

- TP-Link Systems Inc. — AX53 v1 (0)
- TP-Link Systems Inc. — AX55 v4 (0)
- TP-Link Systems Inc. — AX55 v4.6 (0)

## References

- [CNA](https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware)
- [CNA](https://www.tp-link.com/us/support/faq/5025/)
- [CNA](https://www.tp-link.com/us/support/download/archer-ax55/v4/#Firmware)
- [CNA](https://www.tp-link.com/us/support/download/archer-ax55/v4.60/#Firmware)
- [CNA](https://www.tp-link.com/en/support/download/archer-ax55/v4/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.64%
- **EPSS Percentile:** 49.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._