CVE-2025-14756Disclosure(tp-link / archer_mr600)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tp-link archer_mr600 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to service disruption or full compromise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_mr600
  • archer_mr600_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-01-28); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
archer_mr600archer_mr600_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-01-28: 2Mentions · 2026-01-29: 2Mentions · 2026-02-05: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 1Technical Details · 2026-02-05: 101-2801-2902-05
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure2
2026-01-292
Disclosure1Patch1
2026-02-051
Patch1
Full discourse5 posts
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability CVE-2025-14756 found in TP-Link Archer MR600 v5 routers. Immediate firmware update required to prevent potential exploits. Link: https://thedailytechfeed.com/critical-vulnerability-found-in-tp-link-archer-mr600-v5-routers-urgent-firmware-update-advised/ #Vulnerability #Firmware #Update #Exploit #Security #Network #Router #TPLink #Tech #Alert #Patch #Cyber #Protection #Internet #Safety #Device #Wireless #Technology #Risk #Warning

    Post summary

    CVE-2025-14756 presents a critical vulnerability in TP‑Link Archer MR600 v5 routers, and an immediate firmware update is required to mitigate potential exploits.

    0001184
    239 followersView on X
  • iototsecnews@iototsecnews
    Patch

    TP-Link Archer ルーターの脆弱性 CVE-2025-14756 が FIX:任意のシステム・コマンド実行の恐れ https://iototsecnews.jp/2026/01/28/tp-link-archer-router-flaw-exposes-users-to-remote-attacks-and-full-device-control/ TP-Link 製の Archer MR600 v5において、管理権限を持つ攻撃者が任意のシステム・コマンドを実行できてしまうという、きわめて深刻な脆弱性が確認されました。この脆弱性は、ルーターの管理インターフェースにおける入力値の不十分な検証に起因しています。TP-Link は、日本/英語圏のユーザー向けの修正プログラムを、2026年1月26日付で公開しています。ご利用のチームは、ご注意ください。 #Archer #CVE202514756 #Router #TPLink #Vulnerability

    Post summary

    CVE‑2025‑14756 allows attackers with management privileges on TP‑Link Archer MR600 v5 to execute arbitrary system commands due to insufficient input validation. TP‑Link has released a fix (Jan 26, 2026) for Japanese/English users and recommends applying it.

    01000186
    483 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Command Injection Vulnerability, #CVE-2025-14756, affecting #TP-Link Archer MR600 could allow an authenticated attacker to execute arbitrary system commands, leading to service disruption or full control! #Patch #Patch #Patch

    Post summary

    The post warns about CVE-2025-14756, a command‑injection vulnerability in the TP‑Link Archer MR600 that lets an authenticated attacker run arbitrary system commands, potentially leading to service disruption or full control.

    01000275
    7.2K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    TP-Link Archer Vulnerability Let Attackers Take Control Over the Router https://cybersecuritynews.com/tp-link-archer-vulnerability/ "The flaw, tracked as CVE-2025-14756, enables authenticated attackers to execute arbitrary system commands through the device’s admin interface,…"

    Post summary

    The post announces CVE‑2025‑14756 in TP‑Link Archer routers, noting that authenticated users can run arbitrary system commands through the admin interface.

    00000160
    3.4K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    TP-Link Archer MR600 v5 routers affected by CVE-2025-14756, a critical command injection flaw letting authenticated attackers run arbitrary commands via the admin interface, risking full takeover. #Vulnerability https://threatcluster.io/cluster/critical-command-injection-vulnerability-in-tp-link-archer-m-1420c4d3

    Post summary

    The tweet reports that TP‑Link Archer MR600 v5 routers are affected by CVE‑2025‑14756, a critical command‑injection vulnerability allowing authenticated attackers to run arbitrary commands via the admin interface, risking full takeover.

    0000052
    80 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_mr6005.--
OStp-linkarcher_mr600_firmware---

Explore more