CVE-2025-14738 Details
Description
Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.
A vulnerability allowing unauthenticated attackers to download the configuration file from TP-Link WA850RE range extenders, specifically in versions through WA850RE V2_160527 and WA850RE V3_160922. This vulnerability exposes admin credentials and other sensitive information.
Users are advised to update to the latest firmware version. For WA850RE V2, the latest firmware can be downloaded from the TP-Link official website. For WA850RE V3, the firmware is also available on the TP-Link official website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://blog.exodusintel.com/2022/06/23/tp-link-wa850re-unauthenticated-configuration-disclosure-vulnerability/ | TPLink | Third Party Advisory |
| https://www.tp-link.com/us/support/download/tl-wa850re/v2/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/download/tl-wa850re/v3/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/4848/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-287 | Improper Authentication | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tl-wa850re firmware | <= 160527 <= 160922 |
CPE
Remediation
| |
| tp-link tl-wa850re | 2 3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 29, 2026 | Initial Analysis | [email protected] |
| Dec 18, 2025 | New CVE Received | TPLink |