Command injection in TP-Link products - CVE-2025-15518

 

Command injection in TP-Link products - CVE-2025-15518

Published: March 25, 2026


Vulnerability identifier: #VU124533
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-15518
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands on the operating system, impacting confidentiality, integrity and availability of the device.

The vulnerability exists due to improper input handling in the wireless control CLI command when parsing user input. A remote user can provide crafted input to execute arbitrary commands on the operating system, impacting confidentiality, integrity and availability of the device.


Affected software

Archer NX600
Archer NX210
Archer NX200
Archer NX500

How to mitigate CVE-2025-15518

Install security update from vendor's website.

Archer NX600 - addressed in versions 1.3.0 260309, 1.3.0 260311, 1.4.0 260311
Archer NX210 - addressed in versions 1.3.0 260309, 1.3.0 260311
Archer NX200 - addressed in versions 1.3.0 260309, 1.3.0 260311, 1.8.0 260311
Archer NX500 - addressed in versions 1.3.0 260311, 1.5.0 260309

External References

Related Security Bulletins