Executive brief
A security vulnerability has been identified in the TP-Link Archer MR600 v5 router, a device used to provide 4G LTE and Wi-Fi connectivity. An attacker with administrative access to the router's management interface can execute unauthorized commands by exploiting the WireGuard VPN configuration settings. This could lead to a total takeover of the device, allowing the attacker to monitor network traffic, disrupt internet service, or access internal network resources.
Technical details
A command injection vulnerability (CWE-78) exists in the WireGuard client configuration component of the TP-Link Archer MR600 v5. The issue stems from improper neutralization of user-controlled input within the web management interface when applying configuration changes. An attacker must be authenticated with high privileges (administrative account) and have network access to the management interface (typically via the adjacent network). Successful exploitation allows for arbitrary command execution on the underlying operating system, leading to a full compromise of the device's confidentiality, integrity, and availability. The vulnerability is addressed in firmware versions EU_V5_1.7.0 0.9.1 260518 and JP_V5_1.2.0 0.9.1 260519.
Affected products
- TP-Link Archer MR600 v5 (Hardware Version)
Timeline
- 2026-06-05: patched: Fixed firmware released for JP region
- 2026-06-08: disclosed: CVE-2026-8913 published
- 2026-06-08: advisory: TP-Link security advisory published