CVE-2025-15517

EUVD-2025-208937
A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
tp-linkarcher_nx600_firmware
𝑥
< 1.3.0
tp-linkarcher_nx500_firmware
𝑥
< 1.5.0
tp-linkarcher_nx210_firmware
𝑥
< 1.3.0
tp-linkarcher_nx200_firmware
𝑥
< 1.3.0
tp-linkarcher_nx600_firmware
𝑥
< 1.3.0
tp-linkarcher_nx600_firmware
𝑥
< 1.4.0
tp-linkarcher_nx500_firmware
𝑥
< 1.3.0
tp-linkarcher_nx210_firmware
𝑥
< 1.3.0
tp-linkarcher_nx200_firmware
𝑥
< 1.3.0
tp-linkarcher_nx200_firmware
𝑥
< 1.8.0
𝑥
= Vulnerable software versions