Description
A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.
Problem types
CWE-321 Use of Hard-coded Cryptographic Key
Product status
Any version before 1.3.0 Build 260309
Any version before 1.3.0 Build 260311
Any version before 1.4.0 Build 260311
Any version before < 1.5.0 Build 260309
Any version before 1.3.0 Build 260311
Any version before 1.3.0 Build 260309
Any version before 1.3.0 Build 260311
Any version before < 1.3.0 Build 260309
Any version before 1.3.0 Build 260311
Any version before 1.3.0 Build 260311
Any version before 1.8.0 Build 260311
Credits
Saifeldeen Aziz from Cyshield
References
www.tp-link.com/en/support/download/archer-nx200/
www.tp-link.com/en/support/download/archer-nx210/
www.tp-link.com/en/support/download/archer-nx500/
www.tp-link.com/en/support/download/archer-nx600/
www.tp-link.com/us/support/faq/5027/