#VU124076 Key Exchange without Entity Authentication in Archer AX53 - CVE-2025-62501
Published: March 17, 2026
Archer AX53
TP-Link
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the SSH Hostkey misconfiguration issue in the SSH Hostkey functionality. A remote user on the local network can perform a man-in-the-middle (MitM) attack to obtain device credentials and gain access if captured credentials are reused.