Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer Mr600 |
|
| Vendors & Products |
Tp-link
Tp-link archer Mr600 |
Mon, 08 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration changes.Successful exploitation may result in a full compromise of confidentiality, integrity, and availability of the affected device. | |
| Title | Command Injection in TP-Link's Archer MR600 WireGuard Client Configuration | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-06-09T03:55:38.204Z
Reserved: 2026-05-18T23:12:55.471Z
Link: CVE-2026-8913
Updated: 2026-06-08T18:24:51.494Z
Status : Deferred
Published: 2026-06-08T18:16:34.177
Modified: 2026-06-09T13:51:18.770
Link: CVE-2026-8913
No data.
OpenCVE Enrichment
Updated: 2026-06-09T08:56:41Z