VYPR

Archer MR600

by TP-Link

CVEs (3)

  • CVE-2025-14756HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.03

    Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing authenticated attackers to execute system commands with a limited character length via crafted input in the browser developer console, possibly leading to…

  • CVE-2026-8913HigJun 8, 2026
    risk 0.55cvss epss 0.01

    A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute…

  • CVE-2026-12339MedAug 10, 2026
    risk 0.45cvss epss 0.00

    A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequences. An authenticated administrator may overwrite arbitrary files on the system.Successful exploitation may allow arbitrary file…