CVE-2025-15035

Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent attacker to delete arbitrary server file, leading to possible loss of critical system files and service interruption or degraded functionality.This issue affects Archer AXE75 v1.6: ≤ build 20250107.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:archer_axe75_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_axe75:1.6:*:*:*:*:*:*:*

History

09 Mar 2026, 15:27

Type Values Removed Values Added
First Time Tp-link
Tp-link archer Axe75
Tp-link archer Axe75 Firmware
CPE cpe:2.3:o:tp-link:archer_axe75_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_axe75:1.6:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
References () https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/tree/master/2025/PANW-2025-0004 - () https://github.com/PaloAltoNetworks/u42-vulnerability-disclosures/tree/master/2025/PANW-2025-0004 - Third Party Advisory
References () https://www.tp-link.com/en/support/download/archer-axe75/v1/#Firmware - () https://www.tp-link.com/en/support/download/archer-axe75/v1/#Firmware - Product
References () https://www.tp-link.com/jp/support/download/archer-axe75/v1/#Firmware - () https://www.tp-link.com/jp/support/download/archer-axe75/v1/#Firmware - Product
References () https://www.tp-link.com/phppage/preview.php?url=https://www.tp-link.com/en/support/faq/4881/ - () https://www.tp-link.com/phppage/preview.php?url=https://www.tp-link.com/en/support/faq/4881/ - Vendor Advisory
References () https://www.tp-link.com/us/support/download/archer-axe75/v1/#Firmware - () https://www.tp-link.com/us/support/download/archer-axe75/v1/#Firmware - Product

09 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-09 17:15

Updated : 2026-03-09 15:27


NVD link : CVE-2025-15035

Mitre link : CVE-2025-15035

CVE.ORG link : CVE-2025-15035


JSON object : View

Products Affected

tp-link

  • archer_axe75_firmware
  • archer_axe75
CWE
CWE-20

Improper Input Validation