TP-Link Archer C50, V4, and V5 Hard-Coded Credentials Vulnerability Allowing Decryption of Config Files

Vulnerability

A vulnerability exists in the TP-Link Archer C50 models V3 (through 180703), V4 (through 250117), and V5 (through 200407) due to hard-coded DES decryption keys. This flaw enables attackers to decrypt the user configuration files, config.xml.

Impact

Exploitation of this vulnerability could lead to unauthorized decryption of user configuration files, potentially exposing sensitive information.

Remediation

Users are advised to upgrade to a supported TP-Link model that receives automatic updates. Instructions for upgrading can be found on the TP-Link website.

Added: Jul 16, 2025, 8:18 PM
Updated: Jul 16, 2025, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.