CVE-2025-14756: TP-Link Archer MR600 Firmware
High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.
Affected products
- TP-Link Archer MR600 Firmware: before 1.1.0 (fixed in 1.1.0)
Published 2026-01-26. Last modified 2026-06-17.