CVE-2017-11519: TP-Link Archer c9 (2.0) Firmware
Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.
Affected products
- TP-Link Archer c9 (2.0) Firmware: version 160517 only
Published 2017-07-21. Last modified 2026-06-17.