Vulnerability Details CVE-2025-14737
Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527,
≤
WA850RE V3_160922.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 57.3%
CVSS Severity
CVSS v3 Score 8.0
Products affected by CVE-2025-14737
-
cpe:2.3:h:tp-link:tl-wa850re:2
-
cpe:2.3:h:tp-link:tl-wa850re:3
-
cpe:2.3:o:tp-link:tl-wa850re_firmware:-
-
cpe:2.3:o:tp-link:tl-wa850re_firmware:160527
-
cpe:2.3:o:tp-link:tl-wa850re_firmware:160922