Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TP-Link-TL-WR820N-CVE-2025-14175 — Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N. | Kitploit
Tools/GitHubGitHub/cybervinner/tp-link-tl-wr820n-cve-2025-14175
Embedded Systems SecurityIoT SecurityVulnerability AnalysisCryptographyPapers & ResearchLearning & Education
GitHubcybervinner/tp-link-tl-wr820n-cve-2025-14175

TP-Link-TL-WR820N-CVE-2025-14175

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
7 months agoNot yet reviewed

🔐 CVE-2025-14175

Weak Algorithm Support in SSH Server – TP-Link TL-WR820N

CVE Severity CVSS Status License


Overview

This repository documents a security vulnerability identified in the SSH server implementation of the TP-Link TL-WR820N (v2.80) router.

The vulnerability allowed the use of weak cryptographic algorithms, potentially exposing the confidentiality of SSH traffic.
The issue was responsibly disclosed, patched by the vendor, and assigned CVE-2025-14175.


Vulnerability Summary

  • Product: TP-Link TL-WR820N (v2.80)
  • CVE ID: CVE-2025-14175
  • CWE: CWE-327 – Use of a Broken or Risky Cryptographic Algorithm
  • CVSS v4.0: 6.0 (Medium)
  • Attack Vector: Adjacent Network
  • Impact: Confidentiality compromise
  • Status: Fixed in the latest firmware

Responsible Disclosure Timeline

EventDate
Discovery14 June 2025
Reported to Vendor16 June 2025
Fix Released25 Sep 2025
CVE Published29 Dec 2025

Affected & Fixed Versions

StatusFirmware Version
❌ Affected< 1.15.0 Build 250813
✅ Fixed≥ 1.15.0 Build 250813

Technical Scope

  • SSH service permitted the use of weak cryptographic algorithms
  • Vendor-confirmed configuration weakness
  • No exploit code or weaponized proof-of-concept disclosed

⚠️ This repository is intended strictly for educational and research purposes.


References

  • 📄 CVE Record: https://www.cve.org/cverecord?id=CVE-2025-14175
  • 🛡️ TP-Link Security Advisory: https://www.tp-link.com/us/support/faq/4861/
  • 📦 Firmware Downloads: https://www.tp-link.com/in/support/download/tl-wr820n/

Researcher

Vishwa V
Cybersecurity Enthusiast | Student SRM Institute of Science and Technology


⭐ If you find this research useful, consider giving the repository a star.

Download Tool