Skip to content
COOEY

EXPOSURES › CVE-2025-15608

CVE-2025-15608

CRITICAL
DETAIL
SourceNVD · cve Published2026-03-20 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-15608 ↗
⚡ RCE ◐ ZERO-DAY SHAME 50/100 rcezero-day

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions,

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe handling logic, where unvalidated parameters can trigger a stack-based buffer overflow that causes the affected service to crash and, under specific conditions, may enable remote code execution through complex heap-spray techniques. Successful exploitation may result in repeated service unavailability and, in certain scenarios, allow an attacker to gain control of the device.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.