Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitywidely-deployed-product-advisorycredential-access-method

Authenticated Command Injection in TP-Link Archer MR600 v5 (CVE-2025-14756)

Updated 3mo agoFirst seen Jan 28, 20262 sources

TP-Link issued a security advisory for an authenticated command injection vulnerability in the Archer MR600 v5 router’s web-based admin interface, tracked as CVE-2025-14756 with a CVSS 8.5 rating. The flaw stems from insufficient input sanitization in the admin interface component, enabling a logged-in attacker to execute arbitrary system commands by submitting crafted input via the browser’s developer console; while the injected command length is limited, successful exploitation can still result in service disruption or full device compromise.

Affected devices are Archer MR600 v5 units running firmware versions prior to the fixed release (reported as versions below v0001.0 Build 250930 Rel.63611n / older than 1.1.0 and including 0.9.1 and below, depending on versioning notation in the advisory). The reported attack conditions include requiring valid admin credentials and adjacent network access, but the impact is high due to potential complete router takeover; TP-Link’s recommended mitigation is to apply the latest firmware update immediately, and one report notes the model is not sold in the United States, potentially limiting exposure there.

Share:
Authenticated Command Injection in TP-Link Archer MR600 v5 (CVE-2025-14756)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Jan 28, 20265mo ago

TP-Link releases patched firmware for affected Archer MR600 v5 devices

TP-Link made updated firmware available to fix the vulnerability, with affected devices identified as Archer MR600 v5 units running firmware older than 1.1.0 0.9.1 v0001.0 Build 250930 Rel.63611n. The company advised users to download and install the latest firmware from its support channels.

TP-Link discloses CVE-2025-14756 in Archer MR600 v5 routers

TP-Link published a security advisory for CVE-2025-14756, a high-severity authenticated command injection flaw in the web management interface of Archer MR600 v5 routers. The vulnerability could let an authenticated attacker execute system commands and potentially fully compromise the device.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Organizations
1 linked
TP-Link
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.