
TP-Link has issued fixes for several security weaknesses in its Archer NX router products, including a critical one that could allow unauthorized individuals to bypass security measures and install new router software.
Identified as CVE-2025-15517, this flaw affects Archer NX200, NX210, NX500, and NX600 wireless routers. It is due to a vulnerability where authentication is not properly required, allowing attackers to exploit it without needing special access.
“Certain cgi endpoints on the HTTP server lack proper authentication checks, giving unauthorized users access intended for authenticated users,” TP-Link stated when releasing the security patches.
“Attackers can then perform administrative HTTP tasks without being authenticated, including updating router firmware and modifying configuration settings.”
TP-Link also removed a default encryption key (CVE-2025-15605) used in the configuration system. This key allowed attackers who had already gained access to decrypt, alter, and re-encrypt configuration files.
In addition, the company corrected two command injection flaws (CVE-2025-15518 and CVE-2025-15519). These flaws could allow attackers with administrative rights to run any command on the system.
The company is “strongly” urging customers to download and install the newest software update to prevent potential attacks that could exploit these vulnerabilities.
“If you don’t take the recommended actions, the vulnerability will persist. TP-Link will not be liable for consequences that could have been prevented by following this advisory,” it said.
In September, TP-Link was forced to quickly release updates for a zero-day vulnerability that affected many router types after failing to do so following a May 2024 report. This flaw enabled attackers to intercept or change unencrypted data, redirect DNS requests to malicious servers, and insert malicious content into web sessions.
CISA also added two other TP-Link vulnerabilities (CVE-2023-50224 and CVE-2025-9377) to their list of Known Exploited Vulnerabilities in September. These vulnerabilities have been used by the Quad7 botnet to compromise vulnerable routers.
Altogether, the U.S. cybersecurity agency has identified six TP-Link vulnerabilities that are being actively exploited in attacks, the oldest being a directory traversal vulnerability (CVE-2015-3035) affecting many Archer devices.
Texas Attorney General Paxton filed a lawsuit against TP-Link Systems in February, claiming that the company falsely advertised its routers as secure while allowing Chinese government-backed hackers to exploit software vulnerabilities and gain access to user devices.
#authentication #bypass #fix #hole #news #possible #routers #security #serious #tp-link #urges #users — News
© Bulletproof Servers. All rights reserved.