PT-2026-4796 · Tp Link · Archer Mr600
Chuya Hayakawa
·
Published
2026-01-26
·
Updated
2026-03-09
·
CVE-2025-14756
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link Archer MR600 version v5
Description
A command injection issue exists in the admin interface component. Authenticated attackers can execute system commands with a limited character length through crafted input in the browser developer console, potentially causing service disruption or full system compromise. The vulnerability is present when interacting with the admin interface. The vulnerable component allows execution of commands via the browser console.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archer Mr600