ZeroHour
Security Affairspublished ()ingested @securityaffairs

Patch now: TP-Link Archer NX routers vulnerable to firmware takeover

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-50224
Authentication Bypass by Spoofing in TP-Link TL-WR841N Router Exposes Stored Credentials

CVE-2023-50224 is an improper authentication flaw (CWE-290) in the httpd service of the TP-Link TL-WR841N router, which listens on TCP port 80 by default; it was reported through Trend Micro's Zero Day Initiative (ZDI-CAN-19899). A network-adjacent attacker with no credentials can send spoofed authentication data to the web interface, bypassing authentication and disclosing stored credentials (including credentials handled by the device's dropbearpwd component). The attacker gains access to sensitive stored credentials, which can be leveraged for further compromise of the router and connected networks; the flaw has high confidentiality impact but no integrity or availability impact (CVSS 6.5, adjacent-network vector). Owners of TL-WR841N routers are affected, and vendor CPE data additionally enumerates related TP-Link firmware products (e.g., MR6400, TL-WDR3600, TL-WDR4300, TL-WR740N series); no specific vulnerable version ranges were provided in the source data. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-09-03, confirming exploitation in the wild (ransomware use unknown), although no public PoC is known.

Do: Apply firmware updates from TP-Link per vendor instructions as required by the CISA KEV listing (follow BOD 22-01 guidance), and because this is an older router line, verify whether your specific hardware revision still receives firmware, replacing or retiring devices that are end-of-life. Until patched, restrict the web management interface to trusted LAN segments, disable WAN-side/remote management on TCP port 80, and rotate admin and WAN credentials (e.g., PPPoE) that may have been disclosed.

6.516% KEV
  • tp-link tl-wr841n firmware
  • tp-link mr6400 firmware
  • tp-link tl-wdr3600 firmware
  • +9 more
masslikely millions of deployed devices (tens of millions of TL-WR841N units shipped globally; tens of thousands of TP-Link routers visible in public internet…
CVE-2025-15517
+1 in the same advisory: …15605
A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intende

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.

NVD description · AI analysis pending
8.6
group max
3%
  • tp-link archer nx600 firmware
  • tp-link archer nx500 firmware
  • tp-link archer nx210 firmware
  • +1 more
CVE-2025-9377
OS Command Injection in TP-Link Archer C7 (EU) and TL-WR841N/ND (MS) Routers

TP-Link Archer C7 (EU) and TL-WR841N/ND (MS) routers contain an OS command injection vulnerability (CWE-78) in the Parental Control page of the device's web management interface. By submitting crafted input through that page, an attacker can execute arbitrary operating-system commands on the router with device-level privileges. Users of these specific models are affected, and CISA notes the products may be end-of-life (EoL) and/or end-of-service (EoS), which may limit the availability of fixes. The flaw was added to CISA's KEV catalog on 2025-09-03, indicating known active exploitation in the wild; no public proof-of-concept is known and ransomware use has not been confirmed. EPSS estimates a 33.5% probability of exploitation within the next 30 days (98th percentile), a relatively high likelihood given the vulnerability is unscored.

Do: Inventory networks for Archer C7 (EU) and TL-WR841N/ND (MS) routers and apply the latest firmware from TP-Link if an update is offered for the specific hardware variant. Because the devices may be EoL/EoS and a patch may not be available, CISA's required action is to apply vendor mitigations (or BOD 22-01 guidance for federal agencies) or discontinue use of the product; as interim mitigation, disable WAN-side/remote web management, restrict the admin interface to trusted LAN access, and use strong administrator credentials.

8.634% KEV
  • TP-Link Archer C7 (EU) router
  • TP-Link TL-WR841N / TL-WR841ND (MS) router
mass≈1–10 million deployed units combined across the two affected model lines (estimate)
Full article459 words · extracted from securityaffairs.com · click to collapse

TP-Link patched a high severity flaw (CVE-2025-15517) in Archer NX routers that could let attackers bypass authentication and install malicious firmware.

TP-Link issued security updates for its Archer NX router series to fix multiple vulnerabilities, including CVE-2025-15517 (CVSS score of 8.6), a critical authentication bypass flaw. The vulnerability impacts multiple models, including NX200, NX210, NX500, and NX600. The flaw allows attackers to upload new firmware without privileges, creating a high risk of compromise if unpatched.

“A missing authentication check in the HTTP server to certain cgi endpoints allows unauthenticated access intended for authenticated users.” reads the advisory. “An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.”

TP-Link also removed a hardcoded cryptographic key in Configuration Encryption Mechanism, tracked as CVE-2025-15605 (CVSS score of 8.5). The vulnerability allowed authenticated attackers to decrypt configuration files, modify them, and re-encrypt them.

“A hardcoded cryptographic key within its configuration mechanism enables decryption and re-encryption of device configuration data.” reads the advisory. “An authenticated attacker may decrypt configuration files, modify them and re-encrypt them, affecting confidentiality and integrity of device configuration data.”

Below is the list of impacted products/versions and related fixes:

Affected ProductAffected Hardware Versions / Firmware Versions
Archer NX600• v3.0: < 1.3.0 Build 260309
• v2.0: < 1.3.0 Build 260311
• v1.0: < 1.4.0 Build 260311
Archer NX500• v2.0: < 1.5.0 Build 260309
• v1.0: < 1.3.0 Build 260311
Archer NX210• v3.0: < 1.3.0 Build 260309
• v2.0 & v2.20: < 1.3.0 Build 260311
Archer NX200• v3.0: < 1.3.0 Build 260309
• v2.20: < 1.3.0 Build 260311
• v2.0: < 1.3.0 Build 260311
• v1.0: < 1.8.0 Build 260311

The vendor urges customers to download and install the latest firmware version to address these issues.

In September 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added TP-Link Archer C7(EU) and TL-WR841N flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-9377 (CVSS score of 8.6) TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
  • CVE-2023-50224 (CVSS score of 6.5) TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability

This week, the U.S. FCC announced a ban on importing new foreign-made consumer routers, citing unacceptable cyber and national security risks. The decision, backed by Executive Branch assessments, means such devices can no longer be sold or marketed in the U.S. unless they receive special approval.

Routers will be added to the Covered List, with exceptions only for those cleared by the Department of Homeland Security or defense authorities after the Department of Homeland Security or defense authorities verify they pose no threat to communications networks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Archer NX)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/189980/iot/patch-now-tp-link-archer-nx-routers-vulnerable-to-firmware-takeover.html