CVE-2025-15519

Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx600:3.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx500:2.0:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx210:3.0:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx200:3.0:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx600:2.0:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx600:1.0:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx500:1.0:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:tp-link:archer_nx210:2.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx210:2.20:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:tp-link:archer_nx200:2.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx200:2.20:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx200:1.0:*:*:*:*:*:*:*

History

31 Mar 2026, 19:04

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
Summary
  • (es) Manejo inadecuado de entradas en un comando CLI administrativo de gestión de módem en TP-Link Archer NX200, NX210, NX500 y NX600 permite que una entrada manipulada sea ejecutada como parte de un comando del sistema operativo. Un atacante autenticado con privilegios administrativos puede ejecutar comandos arbitrarios en el sistema operativo, afectando la confidencialidad, integridad y disponibilidad del dispositivo.
CPE cpe:2.3:h:tp-link:archer_nx200:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx200:3.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx210:2.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx200:1.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx500:1.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx600:3.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx210:3.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx600:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx500:2.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx210:2.20:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx600:1.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_nx200:2.20:*:*:*:*:*:*:*
First Time Tp-link
Tp-link archer Nx200
Tp-link archer Nx210
Tp-link archer Nx600
Tp-link archer Nx600 Firmware
Tp-link archer Nx200 Firmware
Tp-link archer Nx500
Tp-link archer Nx210 Firmware
Tp-link archer Nx500 Firmware
References () https://www.tp-link.com/en/support/download/archer-nx200/#Firmware - () https://www.tp-link.com/en/support/download/archer-nx200/#Firmware - Product
References () https://www.tp-link.com/en/support/download/archer-nx210/#Firmware - () https://www.tp-link.com/en/support/download/archer-nx210/#Firmware - Product
References () https://www.tp-link.com/en/support/download/archer-nx500/#Firmware - () https://www.tp-link.com/en/support/download/archer-nx500/#Firmware - Product
References () https://www.tp-link.com/en/support/download/archer-nx600/#Firmware - () https://www.tp-link.com/en/support/download/archer-nx600/#Firmware - Product
References () https://www.tp-link.com/us/support/faq/5027/ - () https://www.tp-link.com/us/support/faq/5027/ - Vendor Advisory

23 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 18:16

Updated : 2026-03-31 19:04


NVD link : CVE-2025-15519

Mitre link : CVE-2025-15519

CVE.ORG link : CVE-2025-15519


JSON object : View

Products Affected

tp-link

  • archer_nx210_firmware
  • archer_nx600
  • archer_nx210
  • archer_nx500_firmware
  • archer_nx500
  • archer_nx200_firmware
  • archer_nx200
  • archer_nx600_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')