{"affectedProducts":[{"name":"Archer NX600","vendor":"TP-Link","versions":["v3.0: \u003c 1.3.0 Build 260309","v2.0: \u003c 1.3.0 Build 260311","v1.0: \u003c 1.4.0 Build 260311"]},{"name":"Archer NX500","vendor":"TP-Link","versions":["v2.0: \u003c 1.5.0 Build 260309","v1.0: \u003c 1.3.0 Build 260311"]},{"name":"Archer NX210","vendor":"TP-Link","versions":["v3.0: \u003c 1.3.0 Build 260309","v2.0 \u0026 v2.20: \u003c 1.3.0 Build 260311"]},{"name":"Archer NX200","vendor":"TP-Link","versions":["v3.0: \u003c 1.3.0 Build 260309","v2.20: \u003c 1.3.0 Build 260311","v2.0: \u003c 1.3.0 Build 260311","v1.0: \u003c 1.8.0 Build 260311"]}],"cveId":"CVE-2025-15517","cvssScore":8.6,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-863: Incorrect Authorization","disclosureTimeline":[{"date":"2025-10-05","event":"Discovered","note":""},{"date":"2025-11-13","event":"Vendor notified","note":"Submitted report to security@tp-link.com"},{"date":"2025-11-20","event":"Report acknowlegement","note":""},{"date":"2025-12-03","event":"Vulnerability triaged","note":""},{"date":"2026-01-13","event":"CVE reserved","note":"Reserved CVE-2025-15517"},{"date":"2026-03-23","event":"Public disclosure","note":"CVEs and advisory published"}],"discoveredBy":["Saifeldeen Aziz"],"lastUpdated":"2026-06-09T00:00:00Z","published":"2026-03-23T00:00:00Z","references":[{"label":"TP-Link Security Advisory","url":"https://www.tp-link.com/us/support/faq/5027/"}],"severity":"high","status":"Published","summary":"A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.","title":"Multiple TP-Link Routers: Authorization Bypass in HTTP Server","url":"https://seclab.cyshield.com/advisories/cve-2025-15517/"}