A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.
| Vendor | Product | Versions |
|---|---|---|
| tp-link | archer_nx600_firmware | < 1.3.0, < 1.5.0, < 1.3.0, < 1.3.0, < 1.3.0, < 1.4.0, < 1.3.0, < 1.3.0, < 1.3.0, < 1.8.0 |