logo

Patch now: TP-Link Archer NX routers vulnerable to firmware takeover

ID: 9c2b3b70-f12c-53c2-bed6-4b4da3a84b33

STIX ID: report--9c2b3b70-f12c-53c2-bed6-4b4da3a84b33

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

TP-Link issued firmware updates for Archer NX series routers to address high-severity vulnerabilities including CVE-2025-15517 (authentication bypass allowing unauthenticated firmware upload) and CVE-2025-15605 (hardcoded cryptographic key enabling config decryption); multiple NX200/NX210/NX500/NX600 models and firmware versions are affected and users are urged to install fixes. The report also notes related TP-Link flaws added to CISA's KEV and mentions U.S. regulatory actions concerning the security of consumer routers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.