← Back to CVE List
Vulnerability Intelligence Report
Hardcoded DES Decryption Keys in TP-Link Archer C50 V3/V4/V5 and C20 V5

CVE-2025-6982

unsupported-when-assigned

Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml files.

No Active Exploit Signals
CVSS Base Score
6.9
MEDIUM
EPSS Probability:0.25%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-798 ↗CWE-798 Use of Hard-coded Credentials

Affected Products & Versions

Vendor Product Affected Versions
TP-Link Systems Inc. Archer C50 V3 0 <= 180703 (affected)
TP-Link Systems Inc. Archer C50 V4 0 <= 250117 (affected)
TP-Link Systems Inc. Archer C50 V5 0 <= 200407 (affected)
TP-Link Systems Inc. Archer C20 V5 0 < US_V5_260419 (affected), 0 < EU_V5_260317 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.252%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTP-Link Systems Inc. · Vendor · USA
Reserved2025-07-01T20:09:03
Published2025-07-16T20:01:41
Last Updated2026-04-22T21:24:12

LINK COPIED TO CLIPBOARD