TP-Link Archer NX200
- < 1.3.0 Build 260309
- < 1.3.0 Build 260311
- < 1.8.0 Build 260311
A vulnerability exists in TP-Link Archer NX200, NX210, NX500, and NX600 routers due to a hardcoded cryptographic key in the configuration mechanism. This key allows authenticated attackers to decrypt, modify, and re-encrypt device configuration files, thereby compromising the confidentiality and integrity of the configuration data. The vulnerability affects several hardware and firmware versions across the different router models.
Exploitation of this vulnerability allows for unauthorized decryption and modification of device configuration files, which could lead to unauthorized changes in device settings or behavior.
Users are advised to update to the latest firmware version. Firmware updates can be downloaded from the TP-Link support website for each specific model.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.