Improper Authentication in TP-Link products - CVE-2025-15517
Published: March 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
The vulnerability exists due to improper access control in the HTTP server when handling requests to certain CGI endpoints. A remote attacker can send a specially crafted request to perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
Affected software
Archer NX210
Archer NX200
Archer NX500
How to mitigate CVE-2025-15517
Archer NX210 - addressed in versions 1.3.0 260309, 1.3.0 260311
Archer NX200 - addressed in versions 1.3.0 260309, 1.3.0 260311, 1.8.0 260311
Archer NX500 - addressed in versions 1.3.0 260311, 1.5.0 260309