Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code. The vulnerability arises from improper validation of a packet field whose offset is used to determine the write location in memory. By crafting a packet with a manipulated field offset, an attacker can redirect writes to arbitrary memory locations.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link archer Ax53 Firmware
|
|
| CPEs | cpe:2.3:h:tp-link:archer_ax53:-:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_ax53_firmware:1.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tp-link archer Ax53 Firmware
|
|
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer Ax53 |
|
| Vendors & Products |
Tp-link
Tp-link archer Ax53 |
Tue, 03 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 03 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code. The vulnerability arises from improper validation of a packet field whose offset is used to determine the write location in memory. By crafting a packet with a manipulated field offset, an attacker can redirect writes to arbitrary memory locations.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120. | |
| Title | Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53 | |
| Weaknesses | CWE-122 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published: 2026-02-03T18:47:38.341Z
Updated: 2026-02-04T04:55:57.803Z
Reserved: 2025-10-20T15:59:33.740Z
Link: CVE-2025-59487
No data.
Status : Analyzed
Published: 2026-02-03T19:16:13.367
Modified: 2026-02-11T19:22:25.627
Link: CVE-2025-59487
No data.