CVE-2025-15545
EUVD-2025-20653629.01.2026, 18:16
The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tp-link | archer_re605x_firmware | 𝑥 < 1.2.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration