Security Advisory: Multiple Command Injection Vulnerabilities in Archer Products (CVE-2026-9254, CVE-2026-16348, CVE-2026-78541)
Description of Vulnerabilities and Impacts:
Multiple command injection vulnerabilities have been identified in TP-Link Archer BE800 v1, Archer BE3600 v1, and Archer AX75 v1.
CVE-2026-9254: Command Injection Vulnerability in Parent Control of Multiple Archer Devices
An unauthenticated OS command injection vulnerability exists in the parental control functionality of TP-Link Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.
Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
CVSS v4.0 Score: 8.7/ High
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVE-2026-16348: Command Injection Vulnerability in VPN connection of Archer BE800
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.
Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
CVSS v4.0 Score: 8.5/ High
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVE-2026-78541: Stored Command Injection Vulnerability in Parent Control of Archer BE3600
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution.
Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.
CVSS v4.0 Score: 8.5/ High
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Affected Products/Versions and Fixes:
|
Product |
Hardware version |
Fixed firmware |
CVE |
|
Archer BE800 |
V1 |
1.4.2 Build 260708 |
CVE-2026-9254; CVE-2026-16348 |
|
Archer BE3600 |
V1 |
1.2.6 Build 20260617 |
CVE-2026-9254; CVE-2026-78541 |
|
Archer AX75 |
V1 |
1.1.6 Build 260716 |
CVE-2026-9254 |
Recommendations:
We strongly recommend that users with affected devices take the following actions:
- Follow the instructions to update to the latest firmware version to fix the vulnerabilities:
EN: Download for Archer BE800 | TP-Link
Download for Archer BE3600 | TP-Link
Download for Archer AX75 | TP-Link
US: Download for Archer BE800 | TP-Link
Download for Archer BE3600 | TP-Link
Download for Archer AX75 | TP-Link
KR: Download for Archer BE3600 | TP-Link South Korea
Disclaimer:
This advisory is provided for informational purposes only and is subject to change without notice. The information is provided “as is” without warranties of any kind. TP-Link recommends that customers promptly apply available firmware updates or implement documented workarounds as provided in this advisory. Devices/systems that are not updated or mitigated as described may remain vulnerable, and TP-Link disclaims any responsibility or liability for any damages or losses arising from a failure to implement such updates.
Looking For More
Is this faq useful?
Your feedback helps improve this site.
TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.