Description
This vulnerability in AX53 v1 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.
Problem types
CWE-121 Stack-based buffer overflow
Product status
Any version before 251029
Credits
samuzora
References
www.tp-link.com/en/support/download/archer-ax53/v1/
www.tp-link.com/us/support/faq/5025/