#VU124532 Improper Authentication in TP-Link products - CVE-2025-15517
Published: March 25, 2026
Archer NX600
Archer NX500
Archer NX210
Archer NX200
TP-Link
Description
The vulnerability allows a remote attacker to perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
The vulnerability exists due to improper access control in the HTTP server when handling requests to certain CGI endpoints. A remote attacker can send a specially crafted request to perform privileged HTTP actions without authentication, including firmware upload and configuration operations.