CVE-2025-14737

HIGH
8.0CVSS v3
CVSS v2
0.20% EPSS (exploit probability)
CWE-78CWE

Description

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527,



WA850RE V3_160922.

CVSS v3 vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references