Impact
This vulnerability in the Archer AX53 v1, AX55 v4, and AX55 v4.6 routers is a stack‑based buffer overflow (CWE‑121) caused by insufficient input sanitization in the device’s probe‑handling logic, where unvalidated parameters can trigger a stack‑based buffer overflow that causes the service to crash and, under specific conditions, may enable remote code execution through complex heap‑spray techniques. Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.
Affected Systems
TP‑Link Archer AX53 router, version 1.0 (v1), as well as TP‑Link Archer AX55 router, versions 4 and 4.6, are all affected.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, and an EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that an adversary could exploit the flaw by sending a crafted network probe from an external network to the router, triggering the buffer overflow and potentially executing code on the device. Affected devices include the TP‑Link Archer AX53 v1, AX55 v4, and AX55 v4.6.
OpenCVE Enrichment