A critical zero-day remote code execution (RCE) has been discovered in TP-Link routers. The vulnerability is tracked as CVE-2025-9961.

ByteRay has released a proof-of-concept (PoC) exploit that demonstrates how attackers can bypass Address Space Layout Randomization (ASLR) protections to gain complete control over affected devices. The vulnerability resides in the router's Customer Premises Equipment (CPE) WAN Management Protocol (CWMP) binary , a component of the TR-069 protocol used by service providers for remote device management .
TP-Link Vulnerability: Technical Analysis of PoC Exploit
The issue is related to a stack-based buffer overflow within the cwmp process. ByteRay researchers discovered that by sending a malicious request, they could overwrite the program counter (PC) and seize control of the execution flow. However, the presence of ASLR, a security feature that randomly places the memory addresses of key data areas, presented a significant obstacle. Since the exploit did not involve leaking information to reveal memory layouts, the researchers developed a brute-force strategy. They guessed the base address of the C standard library (libc) to locate the system() function.
See also: Pixie Dust Wi-Fi Attack: Exploiting WPS Routers
A false positive would bring down the cwmp service, but the researchers noted that an attacker with access to the TP-Link control panel could simply restart the service, making a brute-force attack feasible. The attack flow requires the router to be configured to accept the attacker's custom Auto Configuration Server (ACS) . The exploit is delivered via a SetParameterValues request containing the payload.

The final payload uses the return-to-libc (ret2libc) technique to call the system() function with a command argument. This command causes the router to download and execute a malicious binary (e.g., a reverse shell) from a server controlled by the attacker. This gives the attacker full remote access.
PoC Discovery and Release
The ByteRay research team made the discovery. During their analysis, they encountered an issue where the GenieACS platform was corrupting the binary payload, preventing successful exploitation. This forced them to develop a custom ACS emulator capable of faithfully transmitting the exploit code.
See also: SonicWall: Brute force attacks hit firewall configuration backups
The team has published a detailed technical analysis and the full exploit code on GitHub. They state that the release is intended for educational purposes and security research, allowing administrators to test their own devices. Unauthorized use on other systems is illegal.
This vulnerability is critical, as successful exploitation allows full remote code execution on the TP-Link router. This could allow an attacker to intercept traffic, launch further attacks on the local network, or join the device in a botnet.
The research highlights the security risks associated with network-facing management protocols, such as TR-069, where even small parsing errors can escalate into serious threats. The exploit highlights that mitigations, such as ASLR, can sometimes be bypassed with creative attack strategies.
See also: Critical vulnerability in WatchGuard allows code execution

The disclosure of an exploit for vulnerable home devices highlights one thing: remote management protocols are a persistent risk and require re-evaluation. TP-Link router users are urged to monitor for software updates from the manufacturer and apply them as soon as they become available to fix this vulnerability. In addition, CPE isolation, strict ACS rules, and continuous network anomaly detection are recommended. The PoC disclosure confirms the need for secure regulatory standards and end-user; without a coordinated response, these vulnerabilities will allow mass attacks on homes and businesses. Vendors must provide secure defaults, transparent updates, and easy access to guided fixes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
