CVE-2025-14738: Configuration Disclosure Vulnerability in TP-Link WA850RE

Published Dec 18, 2025
·
Updated

Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2160527,

WA850RE V3160922.

Affected Software

6 affected components
TP-Link WA850RE<=V2_160527
TP-Link WA850RE<=V3_160922
All of the following
TP-Link Tl-wa850re Firmware<=160527
TP-Link TL-WA850RE=2
All of the following
TP-Link Tl-wa850re Firmware<=160922
TP-Link TL-WA850RE=3

Event History

Dec 18, 2025
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-14738?

CVE-2025-14738 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive configuration files.

2

How do I fix CVE-2025-14738?

To fix CVE-2025-14738, it is recommended to upgrade to the latest firmware version that addresses this vulnerability.

3

Which devices are affected by CVE-2025-14738?

CVE-2025-14738 affects TP-Link WA850RE devices with firmware versions V2_160527 and V3_160922.

4

What type of vulnerability is CVE-2025-14738?

CVE-2025-14738 is an improper authentication vulnerability that allows unauthenticated attackers to download configuration files.

5

What are the consequences of not addressing CVE-2025-14738?

Failure to address CVE-2025-14738 could lead to unauthorized access to sensitive data within the device's configuration files.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203