Critical Alert 1 Active Exploit Detected Today

CVE-2026-104286 — Fortinet FortiMail Path Traversal Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2025-15517NVD

Vulnerability Summary

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.
Severity Level
UNKNOWN
Published Date
Mar 23, 2026
Last Modified
Mar 24, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.08%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v4.0 Base Metrics — Score 8.6 (HIGH)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None

Affected & Patched Versions

Affected Versions
  • TP-Link Systems Inc. Archer NX600 v3.0 < 1.3.0 Build 260309
  • TP-Link Systems Inc. Archer NX600 v2.0 < 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX600 v1.0 < 1.4.0 Build 260311
  • TP-Link Systems Inc. Archer NX500 v2.0 < < 1.5.0 Build 260309
  • TP-Link Systems Inc. Archer NX500 v1.0 < 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX210 v3.0 < 1.3.0 Build 260309
  • TP-Link Systems Inc. Archer NX210 v2.0 v2.20 < 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX200 v3.0 < < 1.3.0 Build 260309
  • TP-Link Systems Inc. Archer NX200 v2.20 < 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX200 v2.0 < 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX200 v1.0 < 1.8.0 Build 260311
Patched Versions
  • TP-Link Systems Inc. Archer NX600 v3.0 1.3.0 Build 260309
  • TP-Link Systems Inc. Archer NX600 v2.0 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX600 v1.0 1.4.0 Build 260311
  • TP-Link Systems Inc. Archer NX500 v2.0 < 1.5.0 Build 260309
  • TP-Link Systems Inc. Archer NX500 v1.0 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX210 v3.0 1.3.0 Build 260309
  • TP-Link Systems Inc. Archer NX210 v2.0 v2.20 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX200 v3.0 < 1.3.0 Build 260309
  • TP-Link Systems Inc. Archer NX200 v2.20 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX200 v2.0 1.3.0 Build 260311
  • TP-Link Systems Inc. Archer NX200 v1.0 1.8.0 Build 260311
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.
🎁7-Day Free Trial — Try Pro or Team, no card required.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
📈EPSS Spike Alerts — Catch rising risk before it peaks.
🎯Custom EPSS/CVSS — Filter noise, focus on risk.
🛡️Exploit Intel — A 2nd confirmed-exploit signal beyond KEV.
🐙GitHub Issues — Auto-tracked, no duplicates.
📬Weekly Digest — One clean summary, not inbox spam.
🏷️Watchlist Groups — Tag alerts by team (Infra/AppSec/SOC).
💬Webhooks — Slack & Teams integration.
🔀Smart Routing — Critical alerts to one channel, rest to another.
🚫Ad-Free — Uninterrupted experience.