CVE-2025-62404 describes a heap-based buffer overflow vulnerability within the tmpserver modules of TP-Link Archer AX53 v1.0 routers, affecting firmware versions up to 1.3.1 Build 20241120. An authenticated adjacent attacker can exploit this by sending a specially crafted, oversized network packet, potentially leading to a segmentation fault or arbitrary code execution. Rated with a CVSS score of 8.0 (HIGH), this vulnerability has a low attack complexity and requires prior authentication, but can result in high impacts to confidentiality, integrity, and availability. Its FAUCET Risk Score is 91/100, indicating significant potential risk. Currently, there is no evidence of active exploitation, nor is public exploit code available for Metasploit, Nuclei, or ExploitDB. The CVE has garnered minimal community discussion and media coverage, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:o:tp-link:archer_ax53_firmware:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.