logo

TP-Link Archer Router Flaw Exposes Users to Remote Attacks and Full Device Control

ID: cbd30687-6ef5-55a0-9563-8c6a2e8ae63c

STIX ID: report--cbd30687-6ef5-55a0-9563-8c6a2e8ae63c

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Divya

...
...

**TP-Link Archer MR600 v5 command injection (CVE-2025-14756)** — A high‑severity authenticated command injection in the router’s admin interface (CVSS 8.5) allows local network attackers with admin credentials to execute arbitrary system commands and potentially fully compromise devices; TP‑Link released patched firmware v1.1.0 and users are advised to update immediately, change admin credentials, and monitor for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.