CVE-2025-9961PoC

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An authenticated attacker may remotely execute arbitrary code via the CWMP binary on the devices AX10 and AX1500.  The exploit can only be conducted via a Man-In-The-Middle (MITM) attack.  This issue affects AX10 V1/V1.2/V2/V2.6/V3/V3.6: before 1.2.1; AX1500 V1/V1.20/V1.26/V1.60/V1.80/V2.60/V3.6: before 1.3.11.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-14); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-14: 2Mentions · 2026-02-15: 1Mentions · 2026-02-16: 2Mentions · 2026-03-20: 1Mentions · 2026-05-10: 1PoC Mentioned / Linked · 2026-02-14: 2PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-05-10: 1Exploit Tool / Code · 2026-02-14: 1Exploit Tool / Code · 2026-03-20: 1Technical Details · 2026-02-14: 1Technical Details · 2026-03-20: 1Technical Details · 2026-05-10: 102-1402-1502-1603-2005-10
Signal classification3 categories
PoC
342.9%
General
228.6%
Disclosure
228.6%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-142
PoC2
2026-02-151
General1
2026-02-162
Disclosure1General1
2026-03-201
PoC1
2026-05-101
Disclosure1
Full discourse7 posts
  • 0xor0ne@0xor0ne
    PoC

    Authenticated RCE on TP-Link AX10 & AX1500 through CWMP exploitation (CVE-2025-9961) https://blog.byteray.co.uk/exploiting-zero-day-cve-2025-9961-in-the-tp-link-ax10-router-8745f9af9c46 #infosec https://t.co/Vc5sLd64Lq

    Post summary

    The tweet announces an authenticated remote code execution vulnerability (CVE‑2025‑9961) on TP‑Link routers, linking to a blog that likely provides a proof‑of‑concept exploit.

    679945430487.0K
    87.6K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Authenticated RCE on TP-Link AX10/AX1500 via CWMP exploitation https://blog.byteray.co.uk/exploiting-zero-day-cve-2025-9961-in-the-tp-link-ax10-router-8745f9af9c46 #infosec https://t.co/TktYEIoL8M

    Post summary

    The post announces a zero‑day CVE‑2025‑9961 that allows authenticated remote code execution on TP‑Link AX10/AX1500 routers through CWMP. A linked blog provides further exploitation details.

    0201103467.9K
    92.2K followersView on X
  • 0xor0ne@0xor0ne
    PoC

    Authenticated RCE on TP-Link AX10/AX1500 via CWMP exploitation (CVE-2025-9961) https://blog.byteray.co.uk/exploiting-zero-day-cve-2025-9961-in-the-tp-link-ax10-router-8745f9af9c46 #infosec https://t.co/XYvBK43DvU

    Post summary

    A zero‑day authenticated RCE on TP‑Link AX10/AX1500 (CVE‑2025‑9961) has been disclosed via a linked proof‑of‑concept blog, but there is no evidence of active exploitation or available patch.

    022096475.2K
    88.8K followersView on X
  • Smurfs ✘@0xsmurfsr
    PoC

    @0xor0ne Let's GO ! https://github.com/yt2w/CVE-2025-9961

    Post summary

    User shares a GitHub repository likely containing a proof‑of‑concept for CVE‑2025‑9961, with no additional details on exploitation, patches, or debunking.

    02010203.3K
    120 followersView on X
  • Secure.com@Securedotcom
    Disclosure

    @three_cube TP-Link RCE is a total disaster if you're still using default creds. CVE-2025-9961 proves that even "authenticated" paths are weaponizable.

    Post summary

    The post highlights the severity of the TP‑Link RCE vulnerability (CVE‑2025‑9961) and its impact on default credentials, but provides no technical details, patch information, or exploit references.

    00010830
    34 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20841 2 - CVE-2025-55177 3 - CVE-2026-1731 4 - CVE-2025-9961 5 - CVE-2026-22182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top 5 trending CVEs with no additional details or context.

    00010150
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-12725 2 - CVE-2026-25253 3 - CVE-2026-1731 4 - CVE-2026-21508 5 - CVE-2025-9961 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet simply lists five trending CVEs without providing any exploits, patches, technical details, or other actionable information.

    00010141
    1.7K followersView on X

Explore more