CVE-2025-59487 Details
Description
Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code. The vulnerability arises from improper validation of a packet field whose offset is used to determine the write location in memory. By crafting a packet with a manipulated field offset, an attacker can redirect writes to arbitrary memory locations.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.
A heap-based buffer overflow vulnerability has been identified in the TP-Link Archer AX53 v1.0, specifically within the tmpserver modules. This vulnerability allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code. The issue arises from improper validation of a packet field offset, which is used to determine the write location in memory. By crafting a packet with a manipulated field offset, an attacker can redirect memory writes to arbitrary locations.
Users are advised to update to the latest firmware version. The latest firmware can be downloaded from the TP-Link official website or the TP-Link Malaysia website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2285 | CVE | |
| https://talosintelligence.com/vulnerability_reports/ | TPLink | Third Party Advisory |
| https://www.tp-link.com/en/support/download/archer-ax53/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/my/support/download/archer-ax53/v1/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/4943/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link archer ax53 firmware | 1.0 |
CPE
Remediation
| |
| tp-link archer ax53 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 16, 2026 | CVE Modified | CVE |
| Feb 11, 2026 | Initial Analysis | [email protected] |
| Feb 3, 2026 | New CVE Received | TPLink |