CVE-2025-15568
Published: Mar 9, 2026
Modified: Mar 13, 2026
Description
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and impacts confidentiality, integrity and availability of the device. This issue affects Archer AXE75 v1.6/v1.0: through 1.3.2 Build 20250107.
| Vendor | Product | Versions |
|---|---|---|
TP-Link Systems Inc. | Archer AXE75 v1.6/v1.0 | affected 0 - <= 1.3.2 Build 20250107 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now