CVE detail
CVE-2025-15517
A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- 30th March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Iranian state-affiliated threat group Handala Hack has breached FBI director’s Patel’s personal Gmail account and leaked many personal photos and documents. This follows the FBI’s seizure of domains related to Handala Hack’s […]
vendorresearch.checkpoint.comMar 30, 2026, 12:53 PM The security defects could be used to bypass authentication, execute arbitrary commands, and decrypt configuration files.
newswww.securityweek.comMar 27, 2026, 11:42 AMTP-Link patched a high severity flaw (CVE-2025-15517) in Archer NX routers that could let attackers bypass authentication and install malicious firmware. TP-Link issued security updates for its Archer NX router series to fix multiple vulnerabilities, including CVE-2025-15517 (CVSS score of 8.6), a critical authentication bypass flaw. The vulnerability impacts multiple models, including NX200, NX210, NX500, […]
newssecurityaffairs.comMar 25, 2026, 2:44 PM- https://www.tp-link.com/us/support/faq/5027/www.tp-link.com
No excerpt available.
Vendor Advisorywww.tp-link.comMar 23, 2026, 6:16 PM No excerpt available.
Vendor Advisorywww.tp-link.comMar 23, 2026, 6:16 PMNo excerpt available.
Vendor Advisorywww.tp-link.comMar 23, 2026, 6:16 PMNo excerpt available.
Vendor Advisorywww.tp-link.comMar 23, 2026, 6:16 PMNo excerpt available.
Vendor Advisorywww.tp-link.comMar 23, 2026, 6:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-15605CVSS 8.5 · High
A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data.…
- CVE-2025-15519CVSS 8.5 · High
Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operatin…
- CVE-2025-15518CVSS 8.5 · High
Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operatin…
- CVE-2026-12562CVSS 8.7 · High
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerabil…
- CVE-2026-68502CVSS 9.8 · Critical
LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handl…
- CVE-2026-67594CVSS 9.3 · Critical
Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached…