216.73.217.22

CVE-2025-15568

· Published 09/03/2026 17:16 · Modified 09/03/2026 17:16

Labels: CVE-2025-15568 2026-03-09CVE-2025-15568CWE-78f23511db-6c3e-4e32-a477-6aa17d310630

Essential information

Published
09/03/2026 17:16
Modified
09/03/2026 17:16
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and impacts confidentiality, integrity and availability of the device. This issue affects Archer AXE75 v1.6/v1.0: through 1.3.2 Build 20250107.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD
View on NVD

Affected products (CPE)

ProductCPE
tplink / archer axe75 cpe:2.3:a:tplink:archer_axe75:v1.0:*:*:*:*:*:*:*
tplink / archer axe75 cpe:2.3:a:tplink:archer_axe75:v1.6:*:*:*:*:*:*:*

References