CVE-2025-40634: Stack-based buffer overflow in TP-Link Archer AX50
Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions prior to 1.0.15 build 241203 rel61480. This vulnerability allows an attacker to execute arbitrary code on the device over LAN and WAN networks.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40634?
CVE-2025-40634 has been assigned a high severity rating due to its potential for remote code execution.
How do I fix CVE-2025-40634?
To mitigate CVE-2025-40634, update the firmware of the TP-Link Archer AX50 router to version 1.0.15 or later.
What are the potential impacts of CVE-2025-40634?
CVE-2025-40634 allows attackers to execute arbitrary code on the TP-Link Archer AX50 router, leading to complete compromise of the device.
Which devices are affected by CVE-2025-40634?
CVE-2025-40634 affects TP-Link Archer AX50 routers running firmware versions prior to 1.0.15 build 241203 rel61480.
Is CVE-2025-40634 exploitable remotely?
Yes, CVE-2025-40634 is exploitable over both LAN and WAN, making it a significant risk for users.