← Back to news

Patch now: TP-Link Archer NX routers vulnerable to firmware takeover

Security Affairs25/03/2026, 14:44
Read full article →

Summary

AI-Generated

Key Points:

  • TP-Link has patched a critical vulnerability (CVE-2025-15517) in Archer NX routers that allows attackers to bypass authentication and install malicious firmware.
  • The flaw affects multiple models, including NX200, NX210, NX500, and NX600, with a CVSS score of 8.6, posing a significant risk of unauthorized firmware uploads if not addressed.
  • Users are strongly advised to update their router firmware to the latest versions provided by TP-Link to mitigate these vulnerabilities.

Technical Details: CVE-2025-15517 enables unauthenticated access to certain cgi endpoints in the HTTP server, allowing attackers to perform privileged actions without authentication. Additionally, CVE-2025-15605 involves a hardcoded cryptographic key that lets authenticated attackers decrypt and modify configuration files.

MITRE ATT&CK Techniques: None mentioned

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.