Home

Description

A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration changes.Successful exploitation may result in a full compromise of confidentiality, integrity, and availability of the affected device.

PUBLISHED Reserved 2026-05-18 | Published 2026-06-08 | Updated 2026-06-08 | Assigner TPLink




HIGH: 8.5CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

Product status

Default status
unaffected

Any version before EU_V5_1.7.0 0.9.1 260518 rel67803
affected

Any version before JP_V5_1.2.0 0.9.1 260519 rel52362
affected

Credits

Akira Moroo (Ricerca Security, Inc.), Satoki Tsuji (Ricerca Security, Inc.), Anonymous finder

References

www.tp-link.com/en/support/download/archer-mr600/v5/ patch

www.tp-link.com/jp/support/download/archer-mr600/v5/ patch

www.tp-link.com/us/support/faq/5122/ vendor-advisory

cve.org (CVE-2026-8913)

nvd.nist.gov (CVE-2026-8913)

Download JSON