← Vulnerability feed

Vulnerability record · CVE-2025-15551 · published 5 February 2026

CVE-2025-15551: Tp-link archer mr200 firmware vulnerability

Tp Link · Archer Mr200 Firmware

The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge.

5.9 CVSS 4.0 Medium EPSS 0.42% · top 65.9% CWE-95 · CWE-95
5.9CVSS 4.0 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge.

CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-15551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-57040Tp-link tl-wr845n firmware hard-coded credentials vulnerabilityTP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the ro…EPSS 1.2%9.8CVE-2024-46340Tp-link tl-wr845n firmware cleartext storage of sensitive data vulnerabilityTL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after …EPSS 0.34%8.8CVE-2023-37284Tp-link archer c20 firmware improper authentication vulnerabilityImproper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated a…EPSS 0.41%8.5CVE-2026-75616Tp-link archer c20 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configurat…EPSS 2.8%8.0CVE-2024-46341Tp-link tl-wr845n firmware insufficiently protected credentials vulnerabilityTP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a…EPSS 0.24%8.0CVE-2024-50699Tp-link tl-wr845n firmware insufficiently protected credentials vulnerabilityTP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Admi…EPSS 0.42%7.5CVE-2023-30383Tp-link archer c2 v1 firmware classic buffer overflow vulnerabilityTP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discov…EPSS 1.4%7.2CVE-2026-0834Tp-link archer ax53 firmware authentication bypass by spoofing vulnerabilityLogic vulnerability in TP-Link Archer C20 v5, 6.0, Archer AX53 v1.0 and TL-WR841N v13 (TDDP module) allows unauthenticated adjacent attackers to exec…EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2025-15551), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.