TP-Link Archer NX Routers - Critical Firmware Vulnerability Alert
Basically, a flaw in TP-Link routers lets hackers take control if not fixed.
TP-Link has patched a critical vulnerability in Archer NX routers that could allow attackers to take control. Users must update their firmware to protect their devices. This flaw poses significant risks, especially if left unaddressed.
The Flaw
TP-Link has recently issued a patch for a high severity vulnerability (CVE-2025-15517) affecting its Archer NX router series. This flaw allows attackers to bypass authentication, enabling them to upload malicious firmware. The vulnerability has a CVSS score of 8.6, indicating its critical nature. It affects several models, including the NX200, NX210, NX500, and NX600. Essentially, the flaw stems from a missing authentication check in the HTTP server, which allows unauthorized access to certain endpoints meant for authenticated users.
What's at Risk
If exploited, this vulnerability could lead to a complete takeover of the router, allowing attackers to manipulate network traffic and compromise connected devices. The risk is particularly high for users who have not yet updated their firmware. Additionally, another vulnerability (CVE-2025-15605) was patched, which involved a hardcoded cryptographic key that allowed attackers to decrypt and modify configuration files. This further compromises the integrity and confidentiality of the device’s settings.
Patch Status
TP-Link has released security updates for all affected models. Users are urged to download and install the latest firmware versions as soon as possible. The impacted versions include:
- Archer NX600: v3.0 < 1.3.0 Build 260309
- Archer NX500: v2.0 < 1.5.0 Build 260309
- Archer NX210: v3.0 < 1.3.0 Build 260309
- Archer NX200: v3.0 < 1.3.0 Build 260309
These updates are crucial for maintaining the security of the devices and protecting the network from potential threats.
Immediate Actions
Users of TP-Link Archer NX routers should take the following steps:
- Check your router model and firmware version against the list of affected products.
- Download the latest firmware from the official TP-Link website.
- Install the update to ensure your device is protected against these vulnerabilities.
By taking these actions, users can significantly reduce the risk of unauthorized access and maintain the security of their home networks.
Security Affairs