CVE-2025-6982: TP-Link Systems Inc Archer c20 v5

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml files.

Affected products

Published 2025-07-16. Last modified 2026-06-17.