Vulnerability Description
Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wa850Re Firmware | <= 160527 |
| Tp-Link | Tl-Wa850Re | 2 |
Related Weaknesses (CWE)
References
- https://blog.exodusintel.com/2022/06/23/tp-link-wa850re-unauthenticated-configurThird Party Advisory
- https://www.tp-link.com/us/support/download/tl-wa850re/v2/#FirmwareProduct
- https://www.tp-link.com/us/support/download/tl-wa850re/v3/#FirmwareProduct
- https://www.tp-link.com/us/support/faq/4848/Vendor Advisory
FAQ
What is CVE-2025-14738?
CVE-2025-14738 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_...
How severe is CVE-2025-14738?
CVE-2025-14738 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14738?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wa850Re Firmware, Tp-Link Tl-Wa850Re.