{"affectedProducts":[{"name":"Archer NX600","vendor":"TP-Link","versions":["v3.0: \u003c 1.3.0 Build 260309","v2.0: \u003c 1.3.0 Build 260311","v1.0: \u003c 1.4.0 Build 260311"]},{"name":"Archer NX500","vendor":"TP-Link","versions":["v2.0: \u003c 1.5.0 Build 260309","v1.0: \u003c 1.3.0 Build 260311"]},{"name":"Archer NX210","vendor":"TP-Link","versions":["v3.0: \u003c 1.3.0 Build 260309","v2.0 \u0026 v2.20: \u003c 1.3.0 Build 260311"]},{"name":"Archer NX200","vendor":"TP-Link","versions":["v3.0: \u003c 1.3.0 Build 260309","v2.20: \u003c 1.3.0 Build 260311","v2.0: \u003c 1.3.0 Build 260311","v1.0: \u003c 1.8.0 Build 260311"]}],"cveId":"CVE-2025-15605","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":"CWE-321: Use of Hard-coded Cryptographic Key","disclosureTimeline":[{"date":"2025-08-30","event":"Discovered","note":""},{"date":"2025-11-13","event":"Vendor notified","note":"Submitted report to security@tp-link.com"},{"date":"2025-11-20","event":"Report acknowlegement","note":""},{"date":"2025-01-10","event":"Vulnerability triaged","note":""},{"date":"2026-02-02","event":"CVE reserved","note":"Reserved CVE-2025-15605"},{"date":"2026-03-23","event":"Public disclosure","note":"CVEs and advisory published"}],"discoveredBy":["Saifeldeen Aziz"],"lastUpdated":"2026-06-09T00:00:00Z","published":"2026-03-23T00:00:00Z","references":[{"label":"TP-Link Security Advisory","url":"https://www.tp-link.com/us/support/faq/5027/"}],"severity":"high","status":"Published","summary":"A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.","title":"Multiple TP-Link Routers: Hardcoded Configuration Encryption Key","url":"https://seclab.cyshield.com/advisories/cve-2025-15605/"}