PT-2026-27164 · Tp Link · Archer Nx200+3
Saifeldeen Aziz
·
Published
2026-03-23
·
Updated
2026-03-28
·
CVE-2025-15519
CVSS v4.0
8.5
High
| Vector | AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TP-Link Archer NX200
TP-Link Archer NX210
TP-Link Archer NX500
TP-Link Archer NX600
Description
A flaw exists in how input is handled within an administrative command-line interface (CLI) used for modem management. This allows a specially crafted input to be executed as part of an operating system command. An attacker who is already authenticated and has administrative privileges can execute arbitrary commands on the system, potentially compromising the confidentiality, integrity, and availability of the device. The vulnerable component is a modem-management administrative CLI command.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archer Nx200
Archer Nx210
Archer Nx500
Archer Nx600