6.9

CVE-2025-6982

Hardcoded DES Decryption Keys in TP-Link Archer C50 V3/V4/V5 and C20 V5

Use of Hard-coded Credentials in TP-Link Archer C50 V3(

<=

180703)/V4(



<=

250117

)/V5(



<=

200407

), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml files.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerTP-Link Systems Inc.
Produkt Archer C50 V3
Default Statusunaffected
Version <= 180703
Version 0
Status affected
HerstellerTP-Link Systems Inc.
Produkt Archer C50 V4
Default Statusunaffected
Version <= 250117
Version 0
Status affected
HerstellerTP-Link Systems Inc.
Produkt Archer C50 V5
Default Statusunaffected
Version <= 200407
Version 0
Status affected
HerstellerTP-Link Systems Inc.
Produkt Archer C20 V5
Default Statusunaffected
Version 0
Version < US_V5_260419
Status affected
Version 0
Version < EU_V5_260317
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.275
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
f23511db-6c3e-4e32-a477-6aa17d310630 6.9 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.