Use of Hard-coded Credentials in TP-Link Archer C50 V3( <= 180703)/V4( <= 250117 )/V5( <= 200407 ), and C20 V5 (<US_V5_260419 or <EU_V5_260317) allows attackers to decrypt the config.xml files.Referenceshttps://www.tp-link.com/us/support/faq/4538/https://www.tp-link.com/us/support/download/archer-c20/v5/#Firmwarehttps://www.tp-link.com/en/support/download/archer-c20/v5/#Firmware