CVE-2025-15605: TP-Link Archer NX200 Firmware

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.

Affected products

  • TP-Link Archer NX200 Firmware: before 1.3.0 (fixed in 1.3.0); before 1.8.0 (fixed in 1.8.0)
  • TP-Link Archer NX210 Firmware: before 1.3.0 (fixed in 1.3.0)
  • TP-Link Archer NX500 Firmware: before 1.5.0 (fixed in 1.5.0); before 1.3.0 (fixed in 1.3.0)
  • TP-Link Archer NX600 Firmware: before 1.3.0 (fixed in 1.3.0); before 1.4.0 (fixed in 1.4.0)

Published 2026-03-23. Last modified 2026-06-17.