Command Injection Vulnerability in TP-Link WA850RE Router
CVE-2025-14737

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-14737?

The TP-Link WA850RE router is vulnerable to a command injection flaw in its httpd modules, allowing an authenticated adjacent attacker to execute arbitrary commands on the device. This vulnerability affects versions WA850RE V2_160527 and WA850RE V3_160922, which may lead to unauthorized access and manipulation of the system if exploited. It is crucial for users of these affected versions to apply security updates as soon as they are available to mitigate potential risks.

Affected Version(s)

WA850RE 0

WA850RE 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VulnCheck
.