← Vulnerability feed

Vulnerability record · CVE-2025-15607 · published 20 March 2026

CVE-2025-15607: Tp-link archer ax53 firmware command injection vulnerability

Tp Link · Archer Ax53 Firmware

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful exploitation may allow execution of malicious commands and ultimately full control of the device.

7.3 CVSS 4.0 High EPSS 2.0% · top 20.6% CWE-77 · Command injection
7.3CVSS 4.0 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful exploitation may allow execution of malicious commands and ultimately full control of the device.

CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-15607 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2025-62673Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation faul…EPSS 0.55%8.5CVE-2026-30815Tp-link archer ax53 firmware os command injection vulnerabilityAn OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute system c…EPSS 3.1%8.5CVE-2026-30818Tp-link archer ax53 firmware os command injection vulnerabilityAn OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to execute arbitrar…EPSS 2.6%7.7CVE-2025-15608Tp-link archer ax53 firmware stack-based buffer overflow vulnerabilityThis vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalid…EPSS 0.64%7.3CVE-2026-30814Tp-link archer ax53 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation…EPSS 0.56%7.3CVE-2025-58455Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%7.3CVE-2025-59482Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%7.3CVE-2025-59487Tp-link archer ax53 firmware heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentat…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2025-15607), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.