GHSA-q6v4-fwc8-3mpc · Severity: medium — The response coming from TP-Link Archer MR200 v5.2, C20 v6, TL-WR850N v3, and TL-WR845N v4 for...
The response coming from TP-Link Archer MR200 v5.2, C20 v5 and v6, TL-WR850N v3, and TL-WR845N v4 for any request is getting executed by the JavaScript function like eval directly without any check. Attackers can exploit this vulnerability via a Man-in-the-Middle (MitM) attack to execute JavaScript code on the router's admin web portal without the user's permission or knowledge.
Conclusion & alert: CVE-2025-15551 is rated Low Risk (35.8/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.43%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.43% | +0.37% |
| 2 | 2026-06-07 | 0.03% | 0.05% | +0.02% |
| 3 | 2026-03-21 | — | 0.03% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 4.0 | MEDIUM |
|
— | — | f23511db-6c3e-4e32-a477-6aa17d310630 |
| 5.6 | 3.1 | MEDIUM |
|
2.2 | 3.4 | [email protected] |
GHSA-q6v4-fwc8-3mpc · Severity: medium — The response coming from TP-Link Archer MR200 v5.2, C20 v6, TL-WR850N v3, and TL-WR845N v4 for...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tp-link | archer_mr200_firmware | < 250917 | cpe:2.3:o:tp-link:archer_mr200_firmware:*:*:*:*:*:*:*:* |
| tp-link | archer_c20_firmware | < 250630 | cpe:2.3:o:tp-link:archer_c20_firmware:*:*:*:*:*:*:*:* |
| tp-link | tl-wr850n_firmware | < 0.9.1_Build251205 | cpe:2.3:o:tp-link:tl-wr850n_firmware:*:*:*:*:*:*:*:* |
| tp-link | tl-wr845n_firmware | < 251031 | cpe:2.3:o:tp-link:tl-wr845n_firmware:*:*:*:*:*:*:*:* |