Cryptographic Key Vulnerability in TP-Link Archer Devices
CVE-2025-15605
8.5HIGH
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 23 March 2026
What is CVE-2025-15605?
A hardcoded cryptographic key in the configuration mechanism of TP-Link Archer NX200, NX210, NX500, and NX600 devices poses serious security concerns. This vulnerability allows authenticated attackers to decrypt, modify, and re-encrypt the device configuration data, jeopardizing its confidentiality and integrity. Affected users should promptly apply patches available on the TP-Link support site to mitigate potential risks.
Affected Version(s)
Archer NX200 v1.0 Linux 0 < 1.8.0 Build 260311
Archer NX200 v2.0 Linux 0 < 1.3.0 Build 260311
Archer NX200 v2.20 Linux 0 < 1.3.0 Build 260311
