CVE-2025-62501: TP-Link Archer AX53 Firmware

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially crafted man‑in‑the‑middle (MITM) attack. This could enable unauthorized access if captured credentials are reused.This issue affects Archer AX53 v1.0: through 1.3.1 Build 20241120.

Affected products

  • TP-Link Archer AX53 Firmware: version 1.0 only

Published 2026-02-03. Last modified 2026-06-17.