TP-Link Archer NX Firmware Takeover Vulnerabilities

TP-Link Archer NX Firmware Takeover Router Security
Overview
Multiple vulnerabilities in TP-Link Archer NX routers can allow attackers to bypass authentication and upload malicious firmware. Exploitation may result in persistent device compromise and full control over routed traffic and managed settings.
Because these flaws affect internet-connected edge infrastructure, successful compromise can expose downstream users and connected systems to interception, redirection, and botnet abuse.
Technical Specifications
| Field | Details |
|---|---|
| Primary CVE | CVE-2025-15517 |
| CVSS Score | 8.6(High) |
| Additional CVEs | CVE-2025-15605, CVE-2025-15518, CVE-2025-15519 |
| Primary Flaw Type | Authentication bypass in web management interface |
| Secondary Flaw Types | Hardcoded crypto key; command injection |
| Affected Models | Archer NX200, NX210, NX500, NX600 |
| Potential Outcome | Unauthenticated firmware upload, command execution, persistent root control |
Affected Products
- TP-Link Archer NX200
- TP-Link Archer NX210
- TP-Link Archer NX500
- TP-Link Archer NX600
Technical Details
- CVE-2025-15517 enables authentication bypass through missing access controls in CGI management endpoints.
- The bypass can permit unauthenticated firmware upload in vulnerable configurations.
- CVE-2025-15605 involves a hardcoded cryptographic key that can enable config decryption and tampering.
- CVE-2025-15518 and CVE-2025-15519 are command-injection issues that may permit arbitrary OS-level command execution after access.
- Attackers can chain these weaknesses to gain persistent control of router firmware and settings.
Attack Scenario
- An attacker scans for exposed TP-Link Archer NX router management interfaces.
- The attacker exploits authentication bypass to access firmware management paths without valid login.
- A malicious firmware image is uploaded and applied.
- The compromised router is controlled at root/firmware level for persistence.
- Additional command injection and config tampering are used to deepen control and conceal activity.
Impact Assessment
Full router takeover can provide persistent firmware-level control of edge network behavior and administrative functions.
Attackers can perform DNS hijacking, traffic redirection, MITM interception, and potentially inject malicious payloads into network flows.
Compromised routers can be enrolled into botnets, support DDoS operations, and serve as pivot points for lateral movement to internal assets.
Mitigation Strategies
- Apply the latest TP-Link firmware updates immediately for affected Archer NX models.
- Disable remote/WAN management unless strictly required.
- Restrict admin interface access to trusted internal networks only.
- Rotate default/admin credentials and enforce strong authentication hygiene.
- Monitor router configuration, DNS settings, and management logs for unauthorized changes.
- Segment IoT and less-trusted devices from critical enterprise systems.
Resources
Open-Source Reporting
- Security Advisory on Multiple Vulnerabilities on TP-Link Archer NX200, NX210, NX500 and NX600 (CVE-2025-15517 to CVE-2025-15519 and CVE-2025-15605)
- Patch now: TP-Link Archer NX routers vulnerable to firmware takeover
- Patch now: TP-Link Archer NX routers vulnerable to firmware takeover | SOC Defenders
- TP-Link warns users to patch critical router auth bypass flaw
- TP-Link Patches Multiple Flaws Including Authentication Bypass in Archer NX Routers
- NVD - CVE-2025-15517
Last Updated: March 26, 2026