The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 29 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 17:45:00 +0000

Type Values Removed Values Added
Description The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.
Title Insufficient Backup File Upload Input Validation on TP-Link Archer RE605X
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-01-29T17:57:39.087Z

Reserved: 2026-01-20T21:50:48.467Z

Link: CVE-2025-15545

cve-icon Vulnrichment

Updated: 2026-01-29T17:57:36.211Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-29T18:16:07.533

Modified: 2026-01-29T18:54:13.477

Link: CVE-2025-15545

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses