#VU124535 Use of Hard-coded Cryptographic Key in TP-Link products - CVE-2025-15605
Published: March 25, 2026
Archer NX600
Archer NX500
Archer NX210
Archer NX200
TP-Link
Description
The vulnerability allows a remote user to decrypt configuration files, modify them and re-encrypt them, affecting confidentiality and integrity of device configuration data.
The vulnerability exists due to a hardcoded cryptographic key in the configuration encryption mechanism when processing configuration data. A remote user can exploit the static key to decrypt configuration files, modify them and re-encrypt them, affecting confidentiality and integrity of device configuration data.