CVE-2025-15545Disclosure(tp-link / archer_re605x)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_re605x
  • archer_re605x_firmware

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-29); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
archer_re605xarcher_re605x_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-29: 2Mentions · 2026-03-09: 1Technical Details · 2026-01-29: 2Technical Details · 2026-03-09: 101-2903-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-292
Disclosure1General1
2026-03-091
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 TP-Link Archer RE605X, #OS Command Injection, #CVE-2025-15545 (High) https://dailycve.com/tp-link-archer-re605x-os-command-injection-cve-2025-15545-high/

    Post summary

    A new OS Command Injection vulnerability (CVE-2025-15545) with a High CVSS score has been disclosed for the TP‑Link Archer RE605X router; no PoC, exploit, or patch details are mentioned.

    0000030
    166 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15545 Backup Restore Vulnerability Enables Unauthenticated Root Command Injection https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15545

    Post summary

    CVE-2025-15545 is disclosed as a backup‑restore flaw that allows unauthenticated root command injection, but the snippet provides no PoC, exploit code, or patch information.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-15545 The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag … https://www.cve.org/CVERecord?id=CVE-2025-15545

    Post summary

    The post briefly notes a validation flaw in the backup restore function for CVE-2025-15545, without indicating any PoC, exploit, active use, or patch information.

    00000168
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_re605x3.0--
OStp-linkarcher_re605x_firmware---

Explore more