Multiple Vulnerabilities in TP-Link Devices Enable Arbitrary Command Execution
TP-Link has issued a security advisory concerning four high-severity vulnerabilities affecting its Archer series routers.
TP-Link has issued a security advisory concerning four high-severity vulnerabilities affecting its Archer series routers.
The impacted models include the Archer NX200, NX210, NX500, and NX600. These vulnerabilities could allow unauthorized access, enabling the execution of operating system commands and manipulation of sensitive device configurations.
The advisory addresses issues related to authorization bypass, command injection, and cryptographic failures, posing risks to confidentiality, integrity, and availability.
CVE-2025-15517 (CVSS 8.6): Authorization bypass in HTTP server endpoints, allowing unauthenticated actions such as firmware uploads and configuration changes. CVE-2026-15518 (CVSS 8.5): Command injection in the wireless control CLI, enabling authenticated users to execute arbitrary OS commands. CVE-2026-15519 (CVSS 8.5): Similar command injection issue in the modem management CLI, allowing execution of malicious input at the OS level. CVE-2025-15605 (CVSS 8.5): Exposure of a hardcoded cryptographic key, allowing attackers to decrypt, alter, and re-encrypt device configuration data.
TP-Link has issued a security advisory concerning four high-severity vulnerabilities affecting its Archer series routers.
Users are advised to upgrade their firmware to secure their networks. The affected models are not available in the United States. Ensure hardware versions are verified and the appropriate patches applied.
Archer NX600: Update hardware v1.0 to 1.4.0 Build 260311, v2.0 to 1.3.0 Build 260311, v3.0 to 1.3.0 Build 260309. Archer NX500: Update hardware v1.0 to 1.3.0 Build 260311, v2.0 to 1.5.0 Build 260309. Archer NX210: Update hardware v2.0 and v2.20 to 1.3.0 Build 260311, v3.0 to 1.3.0 Build 260309. Archer NX200: Update hardware v1.0 to 1.8.0 Build 260311, v2.0 and v2.20 to 1.3.0 Build 260311, v3.0 to 1.3.0 Build 260309.
Administrators and device owners should promptly verify current firmware versions and apply updates. TP-Link recommends downloading the latest firmware from their official support portal to mitigate these vulnerabilities.
Failure to update may result in network exposure to unauthorized access, configuration changes, or complete device takeover.
Based on reporting by GBHackers.
