Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527,
≤
WA850RE V3_160922.
References
| Link | Resource |
|---|---|
| https://blog.exodusintel.com/2022/06/23/tp-link-wa850re-remote-command-injection-vulnerability/ | Third Party Advisory |
| https://www.tp-link.com/us/support/download/tl-wa850re/v2/#Firmware | Product Release Notes |
| https://www.tp-link.com/us/support/download/tl-wa850re/v3/#Firmware | Product Release Notes |
| https://www.tp-link.com/us/support/faq/4848/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-12-18 18:15
Updated : 2026-01-20 19:05
NVD link : CVE-2025-14737
Mitre link : CVE-2025-14737
CVE.ORG link : CVE-2025-14737
JSON object : View
Products Affected
tp-link
- tl-wa850re
- tl-wa850re_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
