Security Advisory: Multiple Command Injection Vulnerabilities in Archer Products (CVE-2026-9254, CVE-2026-16348, CVE-2026-78541)

Security Advisory
Last updated: August 24, 2026

Description of Vulnerabilities and Impacts:

Multiple command injection vulnerabilities have been identified in TP-Link Archer BE800 v1, Archer BE3600 v1, and Archer AX75 v1.

CVE-2026-9254: Command Injection Vulnerability in Parent Control of Multiple Archer Devices

An unauthenticated OS command injection vulnerability exists in the parental control functionality of TP-Link Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.

Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.

CVSS v4.0 Score: 8.7/ High

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

CVE-2026-16348: Command Injection Vulnerability in VPN connection of Archer BE800

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.

Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.

CVSS v4.0 Score: 8.5/ High

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

CVE-2026-78541: Stored Command Injection Vulnerability in Parent Control of Archer BE3600

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution.

Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.

CVSS v4.0 Score: 8.5/ High

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Affected Products/Versions and Fixes:

Product

Hardware version

Fixed firmware

CVE

Archer BE800

V1

1.4.2 Build 260708

CVE-2026-9254; CVE-2026-16348

Archer BE3600

V1

1.2.6 Build 20260617

CVE-2026-9254; CVE-2026-78541

Archer AX75

V1

1.1.6 Build 260716

CVE-2026-9254

Recommendations:

We strongly recommend that users with affected devices take the following actions:

  1. Follow the instructions to update to the latest firmware version to fix the vulnerabilities:

EN: Download for Archer BE800 | TP-Link

Download for Archer BE3600 | TP-Link

Download for Archer AX75 | TP-Link

US: Download for Archer BE800 | TP-Link

Download for Archer BE3600 | TP-Link

Download for Archer AX75 | TP-Link

KR: Download for Archer BE3600 | TP-Link South Korea

Disclaimer:

This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.

Related FAQs

Looking for More

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >