« Volver al listado

CVE-2025-15517

Estado: AnalizadaAlta (8.6)—

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A (red adyacente) + acceso no autenticado a endpoints CGI críticos (firmware upload, configuración). T1078 por bypass de autenticación; T1565.001 por capacidad de modificar firmware/configuración del dispositivo.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-15517",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-15517",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-23T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.6,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
      "affectedData": [
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX600 v3.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.3.0 Build 260309",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX600 v2.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.3.0 Build 260311",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX600 v1.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.4.0 Build 260311",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX500 v2.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "< 1.5.0 Build 260309",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX500 v1.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.3.0 Build 260311",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX210 v3.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.3.0 Build 260309",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX210 v2.0 v2.20",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.3.0 Build 260311",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX200 v3.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "< 1.3.0 Build 260309",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX200 v2.20",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.3.0 Build 260311",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX200 v2.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.3.0 Build 260311",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Archer NX200 v1.0",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.8.0 Build 260311",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-23T18:16:22.347",
  "references": [
    {
      "url": "https://www.tp-link.com/en/support/download/archer-nx200/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/en/support/download/archer-nx210/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/en/support/download/archer-nx500/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/en/support/download/archer-nx600/#Firmware",
      "tags": [
        "Product"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/us/support/faq/5027/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations."
    },
    {
      "lang": "es",
      "value": "Una comprobación de autenticación faltante en el servidor HTTP en TP-Link Archer NX200, NX210, NX500 y NX600 a ciertos puntos finales cgi permite acceso no autenticado destinado a usuarios autenticados. Un atacante puede realizar acciones HTTP privilegiadas sin autenticación, incluyendo la carga de firmware y operaciones de configuración."
    }
  ],
  "lastModified": "2026-06-17T08:37:56.263",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77429691-1193-4480-A64E-E1FB19D6A073",
              "versionEndExcluding": "1.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx600:3.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "58132EDD-47B7-4E46-B280-FE58A920AE43"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70EF52E9-1D92-4778-99C5-3B76B81681FA",
              "versionEndExcluding": "1.5.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx500:2.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "40D78DBB-CAEA-4C2E-B703-2898B73A0A5E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22EA51B1-332E-48BB-BDBA-09A99ECB942F",
              "versionEndExcluding": "1.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx210:3.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DA336E76-7910-4780-BCA0-1DA2AA7F9418"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48125D02-70B1-4448-BB33-4759FF0E3936",
              "versionEndExcluding": "1.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx200:3.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BD6E8279-6E92-47B5-9EEB-CD83355EF693"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77429691-1193-4480-A64E-E1FB19D6A073",
              "versionEndExcluding": "1.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx600:2.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D75A95F3-D299-4037-A755-A6818169762F"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34DC2394-8F53-4C1C-A2AC-E23CE5CB6D2F",
              "versionEndExcluding": "1.4.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx600:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0D20EAF3-A85A-42B1-AF19-D72292523593"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EC93BA6-FB10-4993-838A-C82FA984B6BB",
              "versionEndExcluding": "1.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx500:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "581891F1-F50F-49B0-AB3D-B56ECF43F78B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22EA51B1-332E-48BB-BDBA-09A99ECB942F",
              "versionEndExcluding": "1.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx210:2.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0C230FE9-FBA9-4DAB-B7C1-2A270F57915C"
            },
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx210:2.20:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FA0FC692-C2F1-4C0C-9502-84852BDCD7E3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48125D02-70B1-4448-BB33-4759FF0E3936",
              "versionEndExcluding": "1.3.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx200:2.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A953B18E-F832-4EE9-8821-4F60DC031715"
            },
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx200:2.20:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "10E43B48-2BA2-45ED-9C43-AAD2B021B3D4"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98759C1B-F1B7-4EAC-BC4B-998ACB4B0C0B",
              "versionEndExcluding": "1.8.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:archer_nx200:1.0:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4D2C0169-5369-42A5-B4E3-E7DBED807789"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}