Patch now: TP-Link Archer NX routers vulnerable to firmware takeover

2026-03-25T20:51:51Zd90dcb22afaf7c7f057f4d35062ce5a4b32a4b17043dc98506ecdcfc981159f0
Archer NXAstraZenecaCVE-2025-15517CVE-2026-3055CitrixDutch Ministry of FinanceFCCHackerOneLapsus$LiteLLMNaviaNetScalerNorth KoreaQualDerm PartnersStoatWaffleTP-LinkTeam 8TeamPCPVS Codecybercrimedata-breachransomwarerouter bansupply-chain

What happened

Multiple high-impact incidents and vulnerabilities reported: TP-Link patched an authentication-bypass/firmware takeover flaw in Archer NX routers (CVE-2025-15517, CVSS ~8.6) and the FCC is moving to ban unapproved foreign-made consumer routers. Citrix released fixes for a critical NetScaler memory overread (CVE-2026-3055, CVSS 9.3) that can leak sensitive data. A supply-chain compromise injected backdoors into LiteLLM releases (v1.82.7–1.82.8), attributed to threat actor TeamPCP, enabling credential theft, lateral movement in Kubernetes, and persistence. Several data breaches were disclosed or

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d90dcb22afaf7c7f057f4d35062ce5a4b32a4b17043dc98506ecdcfc981159f0
Enrichment time
2026-03-25T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Patch now: TP-Link Archer NX routers vulnerable to firmware takeover · Baitaphish