CVE-2025-15607 - CVE House
Back to Database
Status published High CVE-2025-15607

Authenticated Command Injection in mcsd Service of TP-Link Archer AX53

Vulnerability Description

A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allowing log redirection to arbitrary files and concatenation of unvalidated file content into shell commands, enabling authenticated attackers to inject and execute arbitrary commands. Successful exploitation may allow execution of malicious commands and ultimately full control of the device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15607

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • samuzora

Affected Vendor

TP-Link Systems Inc.

View all reports →

Affected Software

AX53 v1
Vulnerable Versions:
0

Timeline

Official Publish: March 20th, 2026
Last Modified: March 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)