Junglewise Threat Intelligence

CVE-2025-62673: TP-Link Archer AX53 and AX12 heap-based buffer overflow in tdpserver

CVE-2025-62673 · Severity: high · CVSS 8 · Published 2026-02-03

Technologies: TP-Link Archer Ax53, TP-Link Archer Ax53 Firmware. Vendors: TP-Link.

Executive brief

The TP-Link Archer AX53 and AX12 are Wi-Fi 6 routers used to provide wireless connectivity in homes and offices. A heap-based buffer overflow vulnerability in the tdpserver network service allows an attacker on the same local network to send a specially crafted packet that crashes the router or potentially executes malicious code, disrupting network access and potentially compromising the device.

Technical details

This is a heap-based buffer overflow vulnerability in the tdpserver module of TP-Link Archer routers. The vulnerable component improperly handles a maliciously formed field within network packets, leading to heap memory corruption. The attack requires network-adjacent access (LAN-based attack vector) and no authentication. A successful exploit can cause a segmentation fault (denial of service) or potentially enable arbitrary code execution with the privileges of the tdpserver process. Patches are available for both affected models.

Affected products

  • TP-Link Archer AX53 v1.0 through 1.3.1 Build 20241120
  • TP-Link Archer AX12 v1.0 through 1.5.1 Build 20260721

Timeline

  • 2026-02-03: disclosed

References

Related threats