Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

TP-Link has disclosed three high-severity command injection vulnerabilities affecting Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers.

The flaws could allow nearby attackers to run arbitrary commands with root privileges, potentially leading to full device compromise and attacks against devices connected to the local network.

The security advisory, last updated on August 24, 2026, tracks the issues as CVE-2026-9254, CVE-2026-16348, and CVE-2026-78541. TP-Link has released firmware updates for all affected products and urges customers to install them promptly.

CVE-2026-9254 is an unauthenticated operating-system command-injection flaw in the parental-control function of the Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 devices.

The vulnerability stems from insufficient filtering and neutralization of special characters in certain parameters. An attacker positioned on the local network could exploit the flaw without logging in to the router.

Successful exploitation enables the injection and execution of arbitrary system commands as the root user, giving the attacker the highest privilege level on the device.

The issue has a CVSS v4.0 score of 8.7 and is rated High. TP-Link warned that exploitation could compromise the confidentiality, integrity, and availability of both the router and the traffic passing through the network.

The second issue, CVE-2026-16348, affects the VPN connection functionality of Archer BE800 V1 routers. It is an authenticated command injection flaw that requires administrative access.

An attacker can inject shell metacharacters through a VPN connection and execute commands with root privileges. Although the vulnerability requires valid administrator access, the impact remains serious.

A successful attack could let threat actors establish persistent backdoors, steal credentials, conduct reconnaissance of the local network, and use the compromised router to target other connected systems. CVE-2026-16348 carries a CVSS v4.0 score of 8.5 and a High severity rating.

The third flaw, CVE-2026-78541, is a stored command injection vulnerability in the parental control module of Archer BE3600 V1 routers. An authenticated attacker with administrative access can create a crafted profile name containing shell metacharacters.

The malicious input is stored on the device. It may be processed unsafely later when the router generates its daily cloud report. This delayed execution path can result in arbitrary commands running on the router.

TP-Link assigned the vulnerability a CVSS v4.0 score of 8.5. The affected firmware versions should be upgraded to the following fixed releases:

CVE Vulnerability Affected Product Fixed Firmware CVSS
CVE-2026-9254 Unauthenticated OS command injection in parental controls Archer BE800, BE3600, AX75 BE800: 1.4.2 Build 260708; BE3600: 1.2.6 Build 20260617; AX75: 1.1.6 Build 260716 8.7
CVE-2026-16348 Authenticated command injection in VPN functionality Archer BE800 1.4.2 Build 260708 8.5
CVE-2026-78541 Stored OS command injection via parental-control profile names Archer BE3600 1.2.6 Build 20260617 8.5

Users should download the newest firmware from TP-Link’s regional support pages, confirm the installed hardware revision before updating, and replace default administrator credentials.

Organizations should also restrict router administration to trusted devices, turn off unnecessary remote management services, and monitor network logs for unexpected configuration changes or outbound traffic.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks appeared first on Cyber Security News.