Vulnerability Description
Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml files.
Related Weaknesses (CWE)
References
- https://www.tp-link.com/en/support/download/archer-c20/v5/#Firmware
- https://www.tp-link.com/us/support/download/archer-c20/v5/#Firmware
- https://www.tp-link.com/us/support/faq/4538/
- https://www.kb.cert.org/vuls/id/554637
FAQ
What is CVE-2025-6982?
CVE-2025-6982 is a documented vulnerability. Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml f...
How severe is CVE-2025-6982?
CVSS scoring is not yet available for CVE-2025-6982. Check NVD for updates.
Is there a patch for CVE-2025-6982?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.