Arbitrary File Deletion Vulnerability in TP-Link Archer AXE75
Vulnerability Description
Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≤ build 20250107.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15035
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Yiheng An, Zhibin Zhang, Haozhe Zhang
References
- https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/tree/master/2025/PANW-2025-0004
- https://www.tp-link.com/us/support/download/archer-axe75/v1/#Firmware
- https://www.tp-link.com/en/support/download/archer-axe75/v1/#Firmware
- https://www.tp-link.com/jp/support/download/archer-axe75/v1/#Firmware
- https://www.tp-link.com/phppage/preview.php?url=https://www.tp-link.com/en/support/faq/4881/
More from TP-Link Systems Inc.
View All →Affected Vendor
TP-Link Systems Inc.
View all reports →