CVE detail
CVE-2025-15545 — CVE-2025-15545
Published 2026-01-29 · Modified 2026-06-17 · Vendor tp-link · Product archer_re605x_firmware · Source nvd
MEDIUM
severity
CVSS-derived band
0.0045
EPSS probability
exploitation probability, 30d
37.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References