CVE-2025-14756
Severity CVSS v4.0:
HIGH
Type:
CWE-77
Command Injection
Publication date:
26/01/2026
Last modified:
09/03/2026
Description
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tp-link:archer_mr600_firmware:*:*:*:*:*:*:*:* | 1.1.0 (excluding) | |
| cpe:2.3:h:tp-link:archer_mr600:5.:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



