CVE-2025-6982 Details
Description
Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml files.
A vulnerability exists in the TP-Link Archer C50 models V3 (through 180703), V4 (through 250117), and V5 (through 200407) due to hard-coded DES decryption keys. This flaw enables attackers to decrypt the user configuration files, config.xml.
Users are advised to upgrade to a supported TP-Link model that receives automatic updates. Instructions for upgrading can be found on the TP-Link website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2025CISA-ADP
Assessed Jul 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/554637 | CVE | |
| https://www.tp-link.com/en/support/download/archer-c20/v5/#Firmware | TPLink | |
| https://www.tp-link.com/us/support/download/archer-c20/v5/#Firmware | TPLink | |
| https://www.tp-link.com/us/support/faq/4538/ | TPLink | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | TPLink |
Affected Products
| Product | Versions |
|---|---|
| TP-Link Archer C50 V3 | <= 180703 |
CPE
Remediation
| |
| TP-Link Archer C50 V4 | <= 180703 |
CPE
Remediation
| |
| TP-Link Archer C50 V5 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | CVE Modified | TPLink |
| Nov 3, 2025 | CVE Modified | CVE |
| Jul 16, 2025 | New CVE Received | TPLink |
Volerion