Command injection in TP-Link products - CVE-2025-15519
Published: March 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands on the operating system, impacting confidentiality, integrity and availability of the device.
The vulnerability exists due to improper input handling in the modem management CLI command when parsing user input. A remote user can provide crafted input to execute arbitrary commands on the operating system, impacting confidentiality, integrity and availability of the device.
Affected software
Archer NX210
Archer NX200
Archer NX500
How to mitigate CVE-2025-15519
Archer NX210 - addressed in versions 1.3.0 260309, 1.3.0 260311
Archer NX200 - addressed in versions 1.3.0 260309, 1.3.0 260311, 1.8.0 260311
Archer NX500 - addressed in versions 1.3.0 260311, 1.5.0 260309