CVE-2025-15551: LAN Code Execution on TP-Link Archer MR200, Archer C20, TL-WR850N and TL-WR845N
The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15551?
CVE-2025-15551 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-15551?
To fix CVE-2025-15551, update the firmware of affected TP-Link devices to the latest version provided by the manufacturer.
What devices are affected by CVE-2025-15551?
CVE-2025-15551 affects TP-Link Archer MR200, Archer C20, TL-WR850N, and TL-WR845N models.
What type of attack does CVE-2025-15551 enable?
CVE-2025-15551 enables attackers to perform remote code execution by exploiting the improper handling of responses in JavaScript.
Is CVE-2025-15551 publicly known?
Yes, CVE-2025-15551 has been publicly disclosed, increasing the risk of potential exploitation.