← Back to CVE List
CVE-2026-8913NVD
Vulnerability Summary
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration changes.Successful exploitation may result in a full compromise of confidentiality, integrity, and availability of the affected device.
CVSS v4.0 Base Metrics — Score 8.5 (HIGH)
Attack VectorAdjacent
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredHigh
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- TP-Link Systems Inc. Archer MR600 v5 < EU_V5_1.7.0 0.9.1 260518 rel67803
- TP-Link Systems Inc. Archer MR600 v5 < JP_V5_1.2.0 0.9.1 260519 rel52362
- TP-Link Systems Inc. Archer MR600 v5 EU_V5_1.7.0 0.9.1 260518 rel67803
- TP-Link Systems Inc. Archer MR600 v5 JP_V5_1.2.0 0.9.1 260519 rel52362