CVE-2025-9961 is a high-severity remote code execution vulnerability affecting TP-Link AX10 and AX1500 routers in the CWMP binary. The available supporting content indicates the issue is associated with CWE-120, consistent with a classic stack-based or heap-based buffer overflow caused by copying input without proper bounds checking. An authenticated attacker can remotely execute arbitrary code on vulnerable devices, but exploitation requires positioning as a man-in-the-middle in the relevant communication path. Affected versions are AX10 V1/V1.2/V2/V2.6/V3/V3.6 before 1.2.1 and AX1500 V1/V1.20/V1.26/V1.60/V1.80/V2.60/V3.6 before 1.3.11.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working exploit for CVE-2025-9961, a stack-based buffer overflow in the CWMP (TR-069) service of TP-Link AX10 and AX1500 routers (AX10 < 1.2.1, AX1500 < 1.3.11). The exploit is implemented in Python (exploit.py) and targets the /cwmpWeb/inform HTTP endpoint on TCP port 7547, which is used by the router's CWMP service. The exploit crafts a malicious SOAP SetParameterValues request to trigger a buffer overflow, using a ret2libc technique to call system() with an attacker-supplied command, resulting in remote code execution (RCE). The script also supports a DoS mode, which attempts to crash the service by sending oversized payloads. The README.md provides detailed usage instructions, technical background, and mitigation advice. The exploit does not require any external dependencies and is operational, providing real RCE or DoS if the target is vulnerable and accessible.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.