{"id":"CVE-2025-14175","title":"A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromi…","summary":"A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromi…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-327"],"vendor":"tp-link","product":"tl-wr820n_firmware","affected":["tl-wr820n_firmware < 1.15.0"],"patched":["tl-wr820n_firmware 1.15.0"],"published":"2025-12-29","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14175","references":[{"url":"https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/in/support/download/tl-wr820n/#Firmware","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/4861/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","exploit-available"],"epss":0.00297,"epssPercentile":0.20166,"exploits":{"github":1,"githubRepos":["https://github.com/CyberVinner/TP-Link-TL-WR820N-CVE-2025-14175"],"checkedAt":"2026-09-30T23:30:07.505Z"},"exploitAvailable":true,"ingestedAt":"2026-09-30T23:29:32.515Z","slug":"CVE-2025-14175","body":"## Overview\n\nA vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromise confidentiality.\n\n## Affected\n\n- `tl-wr820n_firmware < 1.15.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tl-wr820n_firmware 1.15.0`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}