TP-Link Archer Router Flaw Exposes Users to Remote Attacks and Full Device Control
A high command injection vulnerability has been identified in TP-Link's Archer MR600 v5 router, allowing authenticated attackers to execute arbitrary system commands through the device's admin interface.
A high command injection vulnerability has been identified in TP-Link's Archer MR600 v5 router, allowing authenticated attackers to execute arbitrary system commands through the device's admin interface.
The vulnerability, assigned CVE-2025-14756, exists within the admin interface component of the Archer MR600 v5 firmware. It permits attackers with administrative credentials to inject malicious system commands via the browser developer console. Although authentication is required and there are character length restrictions, successful exploitation can lead to full device compromise and network control.
This vulnerability has a CVSS v4.0 score of 8.5 (High severity), indicating a significant risk to affected infrastructure. The attack vector is adjacent (AV:A), necessitating local network access, while the attack complexity is low (AC:L), making it straightforward for authenticated threat actors.
TP-Link's Archer MR600 router, with firmware versions prior to 1.1.0 (Build 250930 Rel.63611n), is vulnerable. Affected versions include v0.9.1 and v0001.0. TP-Link issued the security advisory on Fri, Jan 26, 2026, providing users with critical patch information.
The vulnerability, assigned CVE-2025-14756, exists within the admin interface component of the Archer MR600 v5 firmware.
Affected Model CVE ID Vulnerable Versions CVSS Score Severity
Archer MR600 v5 CVE-2025-14756 <1.1.0 (v0.9.1, v0001.0 Build 250930 Rel.63611n) 8.5 High
TP-Link has released patched firmware to address the vulnerability. Users should download and apply firmware version 1.1.0 or later from TP-Link's official support portal. The update is available for English and Japanese regions; this product is not sold in US markets.
Verify the current firmware version on your Archer MR600 device. Download the latest firmware from the TP-Link Support Portal. Apply the security update immediately. Change administrative credentials after patching. Monitor network activity for suspicious admin interface access.
This vulnerability highlights the importance of maintaining up-to-date firmware on network infrastructure. Unpatched devices remain susceptible to complete compromise, potentially exposing entire networks to threats such as lateral movement and data exfiltration.
Based on reporting by GBHackers.
