Vulnerability Description
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration changes.Successful exploitation may result in a full compromise of confidentiality, integrity, and availability of the affected device.
Related Weaknesses (CWE)
References
- https://www.tp-link.com/en/support/download/archer-mr600/v5/#Firmware
- https://www.tp-link.com/jp/support/download/archer-mr600/v5/#Firmware
- https://www.tp-link.com/us/support/faq/5122/
FAQ
What is CVE-2026-8913?
CVE-2026-8913 is a documented vulnerability. A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authen...
How severe is CVE-2026-8913?
CVSS scoring is not yet available for CVE-2026-8913. Check NVD for updates.
Is there a patch for CVE-2026-8913?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.