logo

Router Takeover: High-Severity Command Injection Flaw Hits TP-Link Archer MR600

ID: 1e09cd7e-4444-5f68-8282-39e42fef099b

STIX ID: report--1e09cd7e-4444-5f68-8282-39e42fef099b

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-28

Date Updated: 2026-04-23

Author: Ddos

...
...

TP-Link issued an advisory for Archer MR600 v5 (CVE-2025-14756), an authenticated command injection flaw in the router’s web admin interface with a CVSS of 8.5; attackers who obtain admin credentials can inject system commands via the browser developer console and potentially fully compromise the device. Devices running firmware older than 1.1.0 0.9.1 v0001.0 Build 250930 Rel.63611n are affected; TP-Link has released a patched firmware and urges immediate updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.