August 14, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-6982NVD

Vulnerability Summary

Use of Hard-coded Credentials in TP-Link Archer C50 V3(

<=

180703)/V4(



<=

250117

)/V5(



<=

200407

), allows attackers to decrypt the config.xml files.
Severity Level
MEDIUM(6.9)
Published Date
Jul 16, 2025
Last Modified
Jul 17, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVSS v4.0 Base Metrics
Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone