TP-Link WA850RE Unauthenticated Configuration Disclosure Vulnerability

Vulnerability

A vulnerability allowing unauthenticated attackers to download the configuration file from TP-Link WA850RE range extenders, specifically in versions through WA850RE V2_160527 and WA850RE V3_160922. This vulnerability exposes admin credentials and other sensitive information.

Impact

Exploitation of this vulnerability leads to unauthorized access to the device's configuration file, including admin credentials and other sensitive data.

Remediation

Users are advised to update to the latest firmware version. For WA850RE V2, the latest firmware can be downloaded from the TP-Link official website. For WA850RE V3, the firmware is also available on the TP-Link official website.

Added: Dec 18, 2025, 6:18 PM
Updated: Dec 18, 2025, 6:18 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
8.4
remediation
7.7
relevance
1.4
threat
6.4
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.