Aller au contenu

Fiche vulnérabilité

CVE-2025-15607 : faille critique tp-link archer ax53 firmware (CVSS 9.8)

Description

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful exploitation may allow execution of malicious commands and ultimately full control of the device.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
20 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • tp-link archer ax53 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE