<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security advisories on Cyshield Seclab</title><link>https://seclab.cyshield.com/advisories/</link><description>Recent content in Security advisories on Cyshield Seclab</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Cyshield.</copyright><lastBuildDate>Tue, 09 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://seclab.cyshield.com/advisories/index.xml" rel="self" type="application/rss+xml"/><item><title>Multiple TP-Link Routers: Authorization Bypass in HTTP Server</title><link>https://seclab.cyshield.com/advisories/cve-2025-15517/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15517/</guid><description>A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.</description></item><item><title>Multiple TP-Link Routers: Hardcoded Configuration Encryption Key</title><link>https://seclab.cyshield.com/advisories/cve-2025-15605/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15605/</guid><description>A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.</description></item><item><title>Multiple TP-Link Routers: Post Authentication Command Injection in CLI controlBF Handler</title><link>https://seclab.cyshield.com/advisories/cve-2025-15518/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15518/</guid><description>Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.</description></item><item><title>Multiple TP-Link Routers: Post Authentication Command Injection in CLI sendAtCmd Handler</title><link>https://seclab.cyshield.com/advisories/cve-2025-15519/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15519/</guid><description>Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.</description></item></channel></rss>