Description

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500 V1/V1.20/V1.26/V1.60/V1.80/V2.60/V3.6: before 1.3.11.

INFO

Published Date :

2025-09-06T06:50:59.558Z

Last Modified :

2025-09-09T03:55:19.062Z

Source :

TPLink
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9961 vulnerability.

Vendors Products
Tp-link
  • Ax10
  • Ax1500
  • Tp-link

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability