CVE-2025-15517Patch(tp-link / archer_nx200)

MEDIUMCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch tp-link archer_nx200 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.

4.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_nx200
  • archer_nx200_firmware
  • archer_nx210
  • archer_nx210_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 9 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 7 mentions (2026-03-25); latest day: 1
  • 12 total mentions across 4 days

Affected systems

Vendors
Products
archer_nx200archer_nx200_firmwarearcher_nx210archer_nx210_firmwarearcher_nx500archer_nx500_firmwarearcher_nx600archer_nx600_firmware

4 versions affected across 8 products

Deep dive

Activity timeline12 mentions / 4d
02457Mentions · 2026-03-25: 7Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Mentions · 2026-04-06: 1Active Exploitation · 2026-03-27: 1Patch / Workaround · 2026-03-25: 6Patch / Workaround · 2026-03-27: 2Technical Details · 2026-03-25: 6Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 103-2503-2703-2804-06
Signal classification3 categories
Patch
866.7%
Disclosure
325.0%
Active Exploitation
18.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-257
Disclosure1Patch6
2026-03-273
Active Exploitation1Patch2
2026-03-281
Disclosure1
2026-04-061
Disclosure1
Full discourse12 posts
  • Xakep.ru@XakepRU
    Patch

    В роутерах TP-Link исправили критическую уязвимость обхода аутентификации TP-Link выпустила обновления прошивки для роутеров серии Archer NX, устранив сразу несколько уязвимостей. Самая серьезная позволяла загрузить на устройства произвольную прошивку. https://xakep.ru/2026/03/27/cve-2025-15517/

    Post summary

    TP‑Link has issued firmware updates for its Archer NX routers to address CVE‑2025‑15517, a critical authentication bypass that enabled arbitrary firmware uploads.

    00001598
    46.1K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos TP-Link ❗ CVE-2025-15605 ❗ CVE-2025-15517 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-tp-link-5/ https://t.co/rD5vC8mJ26

    Post summary

    The post announces two new CVEs (CVE‑2025‑15605, CVE‑2025‑15517) affecting TP‑Link products, directing readers to external links for further information.

    00000237
    6.6K followersView on X
  • The Sovereign Protocol@sovereignexec
    Disclosure

    CVE-2025-15517: TP-Link Archer routers allow unauthenticated firmware takeover. Your home network is your wealth perimeter. Sovereign Protocol: Replace foreign consumer routers immediately. Deploy enterprise-grade hardware. Segment networks. Verify firmware. #TheSovereignProtocol

    Post summary

    The post announces CVE‑2025‑15517, noting that TP‑Link Archer routers can be taken over via unauthenticated firmware updates, and advises users to replace consumer routers with enterprise hardware.

    00000148
    4 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting TP-Link router authentication bypass (CVE-2025-15517) to upload malicious firmware and bridge network boundaries. The compromised devices enable lateral movement across network segments, effectively bypassing perimeter controls. #NetworkSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/tp-link-2026-authentication-bypass-vulnerability

    Post summary

    TP‑Link routers are being exploited in the wild via CVE‑2025‑15517, enabling attackers to upload malicious firmware and move laterally across network segments.

    00000146
    1.9K followersView on X
  • Proficio@proficioinc
    Patch

    TP-Link warns users to patch critical router auth bypass flaw (CVE-2025-15517) via @BleepinComputer #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://www.bleepingcomputer.com/news/security/tp-link-warns-users-to-patch-critical-router-auth-bypass-flaw/

    Post summary

    The post announces that TP‑Link is urging users to apply a patch for a critical router authentication bypass flaw (CVE‑2025‑15517).

    00000176
    1.0K followersView on X
  • SempreUpdate@SempreUpdate
    Disclosure

    Falha de segurança em roteadores TP-Link: CVE-2025-15517 permite invasão sem senha https://sempreupdate.com.br/roteadores-tp-link-falha-de-seguranca-cve-2025-15517/

    Post summary

    The post announces a newly disclosed TP‑Link router vulnerability (CVE‑2025‑15517) that could allow unauthenticated access, but it does not provide PoC, exploit, patch, or active‑exploitation details.

    00000189
    4.7K followersView on X
  • Cyber Daily News@CyberDaily_News
    Patch

    TP-Link patches CVE-2025-15517 (CVSS 8.6) in Archer NX routers - unauthenticated attackers can upload arbitrary firmware via missing auth check on HTTP endpoints. If you run NX200/210/500/600, patch immediately. https://securityaffairs.com/189980/iot/patch-now-tp-link-archer-nx-routers-vulnerable-to-firmware-takeover.html #infosec #IoT #vulnerability

    Post summary

    The post focuses on announcing the availability of a patch for CVE-2025-15517 in TP‑Link Archer NX routers, providing technical details and urging immediate remediation.

    00000186
    12 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Patch

    TP-Link patched critical auth-bypass flaw (CVE-2025-15517) in Archer NX routers allowing unauthenticated firmware upload and full device takeover; additional hardcoded key and command injection bugs also fixed. Patch immediately. #CyberSecurity #Vulnerability #Routers #TPLink https://www.bleepingcomputer.com/news/security/tp-link-warns-users-to-patch-critical-router-auth-bypass-flaw/

    Post summary

    TP‑Link has released a patch for CVE‑2025‑15517, an authentication bypass flaw that allows unauthenticated firmware uploads and full device takeover. The update also fixes hardcoded key and command‑injection bugs.

    00000181
    344 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    TP-Link released firmware updates for Archer NX200, NX210, NX500, and NX600 routers to fix critical authentication bypass (CVE-2025-15517), remove hardcoded cryptographic keys, and patch command injection flaws. #TPLink #RouterFlaws #China https://ift.tt/q4ZdCny

    Post summary

    TP‑Link announced firmware updates for Archer routers that fix a critical authentication bypass (CVE‑2025‑15517), eliminate hardcoded cryptographic keys, and patch command injection issues.

    00000239
    3.8K followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    [Security Affairs] Patch now: TP-Link Archer NX routers vulnerable to firmware takeover. TP-Link patched a high severity flaw (CVE-2025-15517) in Archer NX routers that could let attackers bypass authentication and install malicious firmware. TP-Link... http://ow.ly/FL6G106wlE6

    Post summary

    The post announces that TP‑Link released a patch for CVE‑2025‑15517 on Archer NX routers, a high‑severity flaw that could enable authentication bypass and malicious firmware installation.

    00000153
    2.2K followersView on X
  • EloViral@EloViral
    Patch

    🚨 TP-LINK ALERTA PARA FALHA CRÍTICA EM ROTEADORES ARCHER NX Vulnerabilidade CVE-2025-15517 permite bypass de autenticação e upload de firmware. Atacantes podem assumir controle total do dispositivo sem credenciais. Histórico da TP-Link inclui exploração por botnets como Quad7. Usuários devem atualizar firmware imediatamente e alterar senhas padrão. #Segurança #Roteador #Vulnerabilidade https://www.bleepingcomputer.com/news/security/tp-link-warns-users-to-patch-critical-router-auth-bypass-flaw/

    Post summary

    The alert warns that CVE‑2025‑15517 permits authentication bypass and firmware upload on TP‑Link Archer NX routers, urging users to reboot firmware and change default passwords immediately.

    00000118
    8 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: TP-Link patches critical CVE-2025-15517 in Archer NX200, NX210, NX500, NX600 routers that allowed unauthenticated firmware uploads. https://threatcluster.io/cluster/tp-link-patches-critical-vulnerabilities-in-archer-nx-router-063770cc

    Post summary

    TP‑Link has released a patch for CVE‑2025‑15517, which permits unauthenticated firmware uploads on Archer NX200, NX210, NX500, and NX600 routers.

    00000154
    114 followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_nx2001.0--
HWtp-linkarcher_nx2002.0--
HWtp-linkarcher_nx2002.20--
HWtp-linkarcher_nx2003.0--
OStp-linkarcher_nx200_firmware---
HWtp-linkarcher_nx2102.0--
HWtp-linkarcher_nx2102.20--
HWtp-linkarcher_nx2103.0--
OStp-linkarcher_nx210_firmware---
HWtp-linkarcher_nx5001.0--
HWtp-linkarcher_nx5002.0--
OStp-linkarcher_nx500_firmware---
HWtp-linkarcher_nx6001.0--
HWtp-linkarcher_nx6002.0--
HWtp-linkarcher_nx6003.0--
OStp-linkarcher_nx600_firmware---

Explore more