Description
Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions prior to 1.0.15 build 241203 rel61480. This vulnerability allows an attacker to execute arbitrary code on the device over LAN and WAN networks.
No analysis available yet.
Remediation
Vendor Solution
The vulnerability has been fixed by the TP-Link team in firmware version 1.0.15 build 241203 rel61480.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15816 | Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions prior to 1.0.15 build 241203 rel61480. This vulnerability allows an attacker to execute arbitrary code on the device over LAN and WAN networks. |
References
History
Tue, 20 May 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions prior to 1.0.15 build 241203 rel61480. This vulnerability allows an attacker to execute arbitrary code on the device over LAN and WAN networks. | |
| Title | Stack-based buffer overflow in TP-Link Archer AX50 | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-20T13:30:19.289Z
Reserved: 2025-04-16T08:38:09.209Z
Link: CVE-2025-40634
No data.
Status : Deferred
Published: 2025-05-20T11:15:48.930
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-40634
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
Weaknesses
EUVD