TP-Link Archer RE605X Backup Restore Function Command Injection Vulnerability Allowing Root Execution

Vulnerability

A vulnerability exists in the TP-Link Archer RE605X V3 backup restore function, which fails to properly validate unexpected or unrecognized tags in backup files. This oversight allows crafted files to inject tags that are interpreted by a shell, enabling the execution of arbitrary commands with root privileges. The flaw arises from insufficient validation of backup file contents, creating a vector for command injection attacks.

Impact

Exploitation of this vulnerability leads to unauthorized root-level command execution on the affected device.

Remediation

Users are advised to update to the latest firmware version. The patched firmware can be downloaded from the TP-Link official website, ensuring to select the correct regional site and hardware version.

Added: Jan 29, 2026, 6:19 PM
Updated: Jan 29, 2026, 7:05 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.0
remediation
0.0
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.