CVE Database
/

CVE-2025-9961

Back to search

CVE-2025-9961

Published: Sep 6, 2025

Modified: Feb 26, 2026

PUBLISHED

Description

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500 V1/V1.20/V1.26/V1.60/V1.80/V2.60/V3.6: before 1.3.11.

VendorProductVersions

TP-Link Systems Inc.

AX10 V1/V1.2/V2/V2.6/V3/V3.6

affected
0 - < 1.2.1

TP-Link Systems Inc.

AX1500 V1/V1.20/V1.26/V1.60/V1.80/V2.60/V3.6

affected
0 - < 1.3.11

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now