CVE-2025-14738: Configuration Disclosure Vulnerability in TP-Link WA850RE
Improper authentication vulnerability in TP-Link WA850RE (httpd modules) allows unauthenticated attackers to download the configuration file.This issue affects: ≤ WA850RE V2160527,
≤
WA850RE V3160922.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14738?
CVE-2025-14738 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive configuration files.
How do I fix CVE-2025-14738?
To fix CVE-2025-14738, it is recommended to upgrade to the latest firmware version that addresses this vulnerability.
Which devices are affected by CVE-2025-14738?
CVE-2025-14738 affects TP-Link WA850RE devices with firmware versions V2_160527 and V3_160922.
What type of vulnerability is CVE-2025-14738?
CVE-2025-14738 is an improper authentication vulnerability that allows unauthenticated attackers to download configuration files.
What are the consequences of not addressing CVE-2025-14738?
Failure to address CVE-2025-14738 could lead to unauthorized access to sensitive data within the device's configuration files.