
Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.
This repository documents a security vulnerability identified in the SSH server implementation of the TP-Link TL-WR820N (v2.80) router.
The vulnerability allowed the use of weak cryptographic algorithms, potentially exposing the confidentiality of SSH traffic.
The issue was responsibly disclosed, patched by the vendor, and assigned CVE-2025-14175.
| Event | Date |
|---|---|
| Discovery | 14 June 2025 |
| Reported to Vendor | 16 June 2025 |
| Fix Released | 25 Sep 2025 |
| CVE Published | 29 Dec 2025 |
| Status | Firmware Version |
|---|---|
| ❌ Affected | < 1.15.0 Build 250813 |
| ✅ Fixed | ≥ 1.15.0 Build 250813 |
⚠️ This repository is intended strictly for educational and research purposes.
Vishwa V
Cybersecurity Enthusiast | Student
SRM Institute of Science and Technology
⭐ If you find this research useful, consider giving the repository a star.