PT-2026-4796 · Tp Link · Archer Mr600

Chuya Hayakawa

·

Published

2026-01-26

·

Updated

2026-03-09

·

CVE-2025-14756

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link Archer MR600 version v5
Description A command injection issue exists in the admin interface component. Authenticated attackers can execute system commands with a limited character length through crafted input in the browser developer console, potentially causing service disruption or full system compromise. The vulnerability is present when interacting with the admin interface. The vulnerable component allows execution of commands via the browser console.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14756

Affected Products

Archer Mr600