CVE detail
CVE-2025-14737 — CVE-2025-14737
Published 2025-12-18 · Modified 2026-06-17 · Vendor tp-link · Product tl-wa850re_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0096
EPSS probability
exploitation probability, 30d
58.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527,
≤
WA850RE V3_160922.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References