August 2, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-15568NVD

Vulnerability Summary

A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated attacker with adjacent-network access may be able to perform remote code execution (RCE) when the router is configured with sysmode=ap. Successful exploitation results in root-level privileges and impacts confidentiality, integrity and availability of the device.

This issue affects Archer AXE75 v1.6/v1.0: through 1.3.2 Build 20250107.
Severity Level
HIGH(8.5)
Published Date
Mar 9, 2026
Last Modified
Mar 9, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.26%Probability
Root Weakness (CWE)
The software constructs all or part of an OS command using externally-influenced input, but does not properly neutralize special elements.
CVSS v4.0 Base Metrics
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone