Hardcoded Cryptographic Key in Configuration Encryption Mechanism on TP-Link Archer NX200, NX210, NX500 and NX600
Vulnerability Description
A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15605
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Saifeldeen Aziz from Cyshield
References
- https://www.tp-link.com/en/support/download/archer-nx200/#Firmware
- https://www.tp-link.com/en/support/download/archer-nx210/#Firmware
- https://www.tp-link.com/en/support/download/archer-nx500/#Firmware
- https://www.tp-link.com/en/support/download/archer-nx600/#Firmware
- https://www.tp-link.com/us/support/faq/5027/
More from TP-Link Systems Inc.
View All →Affected Vendor
TP-Link Systems Inc.
View all reports →