CVE-2025-6982: Hardcoded DES Decryption Keys in TP-Link Archer C50 V3/V4/V5 and C20 V5

Published Jul 16, 2025
·
Updated

Use of Hard-coded Credentials in TP-Link Archer C50 V3(

<=

180703)/V4(

<=

250117

)/V5(

<=

200407

), and C20 V5 (<USV5260419 or <EUV5260317) allows attackers to decrypt the config.xml files.

Affected Software

4 affected components
TP-Link Archer C50 V3<=180703
TP-Link Archer C50 V4<=250117
TP-Link Archer C50 V5<=200407
TP-Link Archer C20 V5<US_V5_260419, <EU_V5_260317

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Hardening/mitigation requested in the material is to address the ability to decrypt config.xml files due to hardcoded DES decryption keys and hardcoded credentials in TP-Link Archer C50 V3/V4/V5 and C20 V5; however the provided excerpt does not include any vendor patch identifiers or fixed firmware versions to upgrade to, nor any specific configuration setting to change. No actionable remediation steps can be extracted from the text shown.

Event History

Jul 16, 2025
CVE Published
via MITRE·08:01 PM
Data Sourced
via MITRE·08:01 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Jun 21, 57526
Event
via FIRST·04:28 AM

Frequently Asked Questions

1

What is the severity of CVE-2025-6982?

CVE-2025-6982 has a high severity rating due to the use of hard-coded credentials that can be exploited by attackers.

2

How do I fix CVE-2025-6982?

To mitigate CVE-2025-6982, update your TP-Link Archer C50 router to the latest firmware version provided by TP-Link.

3

What devices are affected by CVE-2025-6982?

CVE-2025-6982 affects TP-Link Archer C50 V3, V4, and V5 models up to specific firmware versions.

4

What is the impact of CVE-2025-6982?

The impact of CVE-2025-6982 allows attackers to decrypt sensitive config.xml files, potentially compromising network security.

5

Is it safe to use TP-Link Archer C50 devices affected by CVE-2025-6982?

It is not safe to use affected TP-Link Archer C50 devices without applying the necessary firmware updates to address CVE-2025-6982.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203