A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 22
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Tp-Link Archer_Nx600_Firmware
cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*
|
— |
1.3.0
|
|
Tp-Link Archer_Nx600
cpe:2.3:h:tp-link:archer_nx600:3.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx500_Firmware
cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*
|
— |
1.5.0
|
|
Tp-Link Archer_Nx500
cpe:2.3:h:tp-link:archer_nx500:2.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx210_Firmware
cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*
|
— |
1.3.0
|
|
Tp-Link Archer_Nx210
cpe:2.3:h:tp-link:archer_nx210:3.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx200_Firmware
cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*
|
— |
1.3.0
|
|
Tp-Link Archer_Nx200
cpe:2.3:h:tp-link:archer_nx200:3.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx600_Firmware
cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*
|
— |
1.3.0
|
|
Tp-Link Archer_Nx600
cpe:2.3:h:tp-link:archer_nx600:2.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx600_Firmware
cpe:2.3:o:tp-link:archer_nx600_firmware:*:*:*:*:*:*:*:*
|
— |
1.4.0
|
|
Tp-Link Archer_Nx600
cpe:2.3:h:tp-link:archer_nx600:1.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx500_Firmware
cpe:2.3:o:tp-link:archer_nx500_firmware:*:*:*:*:*:*:*:*
|
— |
1.3.0
|
|
Tp-Link Archer_Nx500
cpe:2.3:h:tp-link:archer_nx500:1.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx210_Firmware
cpe:2.3:o:tp-link:archer_nx210_firmware:*:*:*:*:*:*:*:*
|
— |
1.3.0
|
|
Tp-Link Archer_Nx210
cpe:2.3:h:tp-link:archer_nx210:2.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx210
cpe:2.3:h:tp-link:archer_nx210:2.20:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx200_Firmware
cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*
|
— |
1.3.0
|
|
Tp-Link Archer_Nx200
cpe:2.3:h:tp-link:archer_nx200:2.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx200
cpe:2.3:h:tp-link:archer_nx200:2.20:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Archer_Nx200_Firmware
cpe:2.3:o:tp-link:archer_nx200_firmware:*:*:*:*:*:*:*:*
|
— |
1.8.0
|
|
Tp-Link Archer_Nx200
cpe:2.3:h:tp-link:archer_nx200:1.0:*:*:*:*:*:*:*
|
— | — |