AI description
CVE-2025-15519 describes an improper input handling vulnerability found in a modem-management administrative command-line interface (CLI) on several TP-Link Archer router models, specifically the NX200, NX210, NX500, and NX600. This flaw enables an authenticated attacker with administrative privileges to inject and execute arbitrary operating system commands. By exploiting this vulnerability, an attacker could compromise the confidentiality, integrity, and availability of the affected device.
- Description
- Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Analyzed
- Products
- archer_nx600_firmware, archer_nx500_firmware, archer_nx210_firmware, archer_nx200_firmware
CVSS 4.0
- Type
- Secondary
- Base score
- 8.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 7.2
- Impact score
- 5.9
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- f23511db-6c3e-4e32-a477-6aa17d310630
- CWE-78
- Hype score
- Not currently trending
TP-Link has released patches for CVE-2025-15519 and CVE-2025-15605 https://t.co/rz6s1oivyg via @HostingTech https://t.co/aDE11pQXuv
@HostingTechNet
28 Mar 2026
98 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
TP-Linkが無線LANルータArcher NXシリーズの乗っ取りが可能な脆弱性を修正。CVE-2025-15517は管理画面の一部CGIエンドポイントにおける認証の欠如。ハードコードされた暗号鍵CVE-2025-15605、adminからのコマンドインジェ
@__kokumoto
26 Mar 2026
904 Impressions
2 Retweets
6 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "77429691-1193-4480-A64E-E1FB19D6A073",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx600:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "58132EDD-47B7-4E46-B280-FE58A920AE43",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "70EF52E9-1D92-4778-99C5-3B76B81681FA",
"versionEndExcluding": "1.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx500:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "40D78DBB-CAEA-4C2E-B703-2898B73A0A5E",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "22EA51B1-332E-48BB-BDBA-09A99ECB942F",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx210:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "DA336E76-7910-4780-BCA0-1DA2AA7F9418",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "48125D02-70B1-4448-BB33-4759FF0E3936",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx200:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "BD6E8279-6E92-47B5-9EEB-CD83355EF693",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "77429691-1193-4480-A64E-E1FB19D6A073",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx600:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "D75A95F3-D299-4037-A755-A6818169762F",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "34DC2394-8F53-4C1C-A2AC-E23CE5CB6D2F",
"versionEndExcluding": "1.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx600:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0D20EAF3-A85A-42B1-AF19-D72292523593",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1EC93BA6-FB10-4993-838A-C82FA984B6BB",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx500:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "581891F1-F50F-49B0-AB3D-B56ECF43F78B",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "22EA51B1-332E-48BB-BDBA-09A99ECB942F",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx210:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "0C230FE9-FBA9-4DAB-B7C1-2A270F57915C",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:tp-link:archer_nx210:2.20:*:*:*:*:*:*:*",
"matchCriteriaId": "FA0FC692-C2F1-4C0C-9502-84852BDCD7E3",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "48125D02-70B1-4448-BB33-4759FF0E3936",
"versionEndExcluding": "1.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx200:2.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A953B18E-F832-4EE9-8821-4F60DC031715",
"vulnerable": false
},
{
"criteria": "cpe:2.3:h:tp-link:archer_nx200:2.20:*:*:*:*:*:*:*",
"matchCriteriaId": "10E43B48-2BA2-45ED-9C43-AAD2B021B3D4",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "98759C1B-F1B7-4EAC-BC4B-998ACB4B0C0B",
"versionEndExcluding": "1.8.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:archer_nx200:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "4D2C0169-5369-42A5-B4E3-E7DBED807789",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]