Security vulnerabilities have been discovered in popular TP-Link routers, exposing users to serious risks.

The vulnerabilities were discovered by security researcher “The Veteran” and allow remote attackers to bypass authentication and gain control of devices without the need for valid credentials.
See also: React Router vulnerability allows WAF bypass attacks
Let's take a closer look at the vulnerabilities in TP-Link routers:
CVE-2025-29648: SQL Injection Vulnerability in TP-Link EAP120
The first vulnerability affects the TP-Link EAP120 router (version 1.0). According to the researcher, the login dashboard fails to properly sanitize user input in authentication fields. As a result, an unauthorized attacker can inject malicious SQL statements through these fields.
Ultimately, the attacker could bypass authentication and potentially gain administrator access to the device.
CVE-2025-29649: SQL Injection Vulnerability in TP-Link TL-WR840N
The TP-Link TL-WR840N router (version 1.0) is vulnerable to another SQL Injection vulnerability. Here too, the login dashboard accepts unsanitized input in the username and password fields, allowing an unauthenticated attacker to inject arbitrary SQL code.
See also: DrayTek router vulnerability actively exploited
This can bypass login controls and provide access to the TP-Link router's administrative interface without valid credentials.
CVE-2025-29650: SQL Injection Vulnerability in TP-Link M7200 4G LTE Mobile Wi-Fi Router
This vulnerability affects the TP-Link M7200 4G LTE Mobile Wi-Fi Router with firmware version 1.0.7 Build 180127 Rel.55998n. The device's login interface does not properly sanitize input in the username and password, allowing an unauthenticated attacker to inject malicious SQL statements.
Exploitation could lead to unauthorized access to the router's management console.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CVE-2025-29653: SQL Injection Vulnerability in TP-Link M7450 4G LTE Mobile Wi-Fi Router
The TP-Link M7450 4G LTE Mobile Wi-Fi Router, specifically firmware version 1.0.2 Build 170306 Rel.1015n, is also vulnerable to an SQL injection vulnerability via the username and password fields on its login page. An unauthorized attacker could exploit this vulnerability to inject arbitrary SQL commands, potentially leading to a complete breach of the device's administrative functions.
See also: How to tell if your Wi-Fi router has been hacked?
The above vulnerabilities in TP-Link routers are very dangerous and could allow an attacker to:
- Monitors and interferes with network traffic
- Modifies DNS settings to redirect users to malicious websites
- Uses the compromised router to attack other devices
- Gain access to sensitive information transmitted over the network
Protection
- Change default administrator credentials
- Disable remote management
- Firmware update to the latest available version
- Using network monitoring tools to detect unusual activity
- Monitor for upcoming patches and apply them immediately
- Use firewall and VPN for additional security
- If you suspect your Wi-Fi router has been compromised, reset it to factory settings and set up new, strong credentials immediately.
Source: cybersecuritynews.com
