CVE-2025-15551: TP-Link Archer c20 Firmware
Medium severity, CVSS 5.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge.
Affected products
- TP-Link Archer c20 Firmware: before 250630 (fixed in 250630)
- TP-Link Archer MR200 Firmware: before 250917 (fixed in 250917)
- TP-Link Tl-WR845N Firmware: before 251031 (fixed in 251031)
- TP-Link Tl-WR850N Firmware: before 0.9.1_Build251205 (fixed in 0.9.1_Build251205)
Published 2026-02-05. Last modified 2026-06-17.