CVE-2025-40634 Details
Description
Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions prior to 1.0.15 build 241203 rel61480. This vulnerability allows an attacker to execute arbitrary code on the device over LAN and WAN networks.
A stack-based buffer overflow vulnerability has been identified in the 'conn-indicator' binary of the TP-Link Archer AX50 router. This vulnerability affects firmware versions prior to 1.0.15 build 241203 rel61480 and allows an attacker to execute arbitrary code on the device. The issue arises from the binary running with root privileges, creating a significant security risk. Exploitation can occur over both LAN and WAN networks.
Users can upgrade to TP-Link Archer AX50 firmware version 1.0.15 build 241203 rel61480 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 20, 2025CISA-ADP
Assessed May 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/stack-based-buffer-overflow-tp-link-archer-ax50 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TP-Link Archer AX50 | < 1.0.15 build 241203 rel61480 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 20, 2025 | New CVE Received | [email protected] |
Volerion