Junglewise Threat Intelligence

CVE-2025-15608: TP-Link Archer AX53 and AX55 stack overflow in tdpServer

CVE-2025-15608 · Severity: critical · CVSS 9.8 · Published 2026-03-20

Technologies: TP-Link Archer Ax53, TP-Link Archer Ax53 Firmware, TP-Link Archer AX55. Vendors: TP-Link.

Executive brief

A vulnerability exists in several TP-Link Archer router models that could allow an attacker to remotely crash the device or potentially take full control of it. These routers are commonly used to provide internet connectivity and manage home or small business networks. If exploited, an attacker could disrupt internet service or gain unauthorized access to the device's management functions and network traffic.

Technical details

A stack-based buffer overflow (CWE-121) exists in the 'tdpServer' module of TP-Link Archer AX53 v1, AX55 v4, and AX55 v4.6 routers. The flaw is caused by insufficient input sanitization within the device's probe handling logic when processing unvalidated parameters. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to trigger the overflow. Successful exploitation can lead to a service crash (Denial of Service) or, through complex heap-spray techniques, remote code execution. Firmware updates are available to address this issue.

Affected products

  • TP-Link Archer AX53 v1 before 251029
  • TP-Link Archer AX55 v4 before (US)_V4_251030
  • TP-Link Archer AX55 v4.6 before (US)_V4.6_251030

Timeline

  • 2026-03-20: disclosed
  • 2026-03-20: advisory

References

Related threats