Use of Hard-coded Cryptographic Key in TP-Link products - CVE-2025-15605
Published: March 25, 2026
Vulnerability details
The vulnerability allows a remote user to decrypt configuration files, modify them and re-encrypt them, affecting confidentiality and integrity of device configuration data.
The vulnerability exists due to a hardcoded cryptographic key in the configuration encryption mechanism when processing configuration data. A remote user can exploit the static key to decrypt configuration files, modify them and re-encrypt them, affecting confidentiality and integrity of device configuration data.
Affected software
Archer NX210
Archer NX200
Archer NX500
How to mitigate CVE-2025-15605
Archer NX210 - addressed in versions 1.3.0 260309, 1.3.0 260311
Archer NX200 - addressed in versions 1.3.0 260309, 1.3.0 260311, 1.8.0 260311
Archer NX500 - addressed in versions 1.3.0 260311, 1.5.0 260309