logo

Master Keys and Open Backdoors: TP-Link Issues Urgent Patch for Archer NX-Series Routers

ID: e6ba2bb7-4937-54d5-ab4f-274c22037321

STIX ID: report--e6ba2bb7-4937-54d5-ab4f-274c22037321

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** TP-Link has released critical firmware updates for Archer NX200, NX210, NX500, and NX600 routers to address several high-severity vulnerabilities — including an unauthenticated HTTP endpoint that permits privileged actions (CVE-2025-15517, CVSS 8.6), administrative command injection flaws requiring admin privileges (CVE-2026-15518 & CVE-2026-15519), and a hardcoded cryptographic key that can decrypt and re-encrypt device configuration (CVE-2025-15605) — and strongly urges affected users to download and apply the vendor patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.