CVE-2025-40634: TP-Link Link Archer AX50
Critical severity, CVSS 9.2. EPSS: 0.7% chance of exploitation in the next 30 days.
Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions prior to 1.0.15 build 241203 rel61480. This vulnerability allows an attacker to execute arbitrary code on the device over LAN and WAN networks.
Affected products
- TP-Link Link Archer AX50
Published 2025-05-20. Last modified 2026-06-17.