August 2, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-15517NVD

Vulnerability Summary

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
Severity Level
UNKNOWN
Published Date
Mar 23, 2026
Last Modified
Mar 24, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.08%Probability
Root Weakness (CWE)
N/A