« Volver al listado

CVE-2025-15545

Estado: AnalizadaAlta (7.3)—

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A (red adyacente) + PR:H sugiere T1210. Ejecución de comandos shell arbitrarios con privilegios root confirmado en descripción. La vulnerabilidad requiere acceso a función de restauración (PR:H) en red adyacente, permitiendo ejecución de código y escalada a root.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-15545",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-15545",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-30T04:55:41.504271Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "attackRequirements": "NONE",
          "privilegesRequired": "HIGH",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
      "affectedData": [
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer RE605X",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "(EU)_V3_20260113, (US)_V3_20260126",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-01-29T18:16:07.533",
  "references": [
    {
      "url": "https://nico-security.com/posts/cve-2025-15545",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/en/support/download/re605x/v3/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/us/support/download/re605x/v3/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/us/support/faq/4929/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability."
    },
    {
      "lang": "es",
      "value": "La función de restauración de copias de seguridad no valida correctamente las etiquetas inesperadas o no reconocidas dentro del archivo de copia de seguridad. Cuando se restaura un archivo así manipulado, la etiqueta inyectada es interpretada por un shell, permitiendo la ejecución de comandos arbitrarios con privilegios de root. La explotación exitosa permite al atacante obtener ejecución de comandos a nivel de root, comprometiendo la confidencialidad, integridad y disponibilidad."
    }
  ],
  "lastModified": "2026-06-17T08:37:59.663",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_re605x_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F61E7823-DC9F-4C95-B20D-C3315A5897C3",
              "versionEndExcluding": "1.2.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_re605x:3.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D3E44748-3860-40AE-8BAC-608FF6633189"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}