TP-Link has identified three critical command injection vulnerabilities affecting its Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. These vulnerabilities are of high severity, enabling attackers located near the routers to execute arbitrary commands with elevated root privileges. This could lead to a complete takeover of the device and potential attacks on other devices within the local network.
Details of the Vulnerabilities
The flaws, tracked as CVE-2026-9254, CVE-2026-16348, and CVE-2026-78541, were last updated in a security advisory on August 24, 2026. TP-Link has addressed these issues by releasing firmware updates for all affected models, strongly advising users to implement these updates without delay.
CVE-2026-9254 is an unauthenticated command injection flaw found within the parental control function of the Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The vulnerability arises from inadequate filtering of special characters in certain parameters, allowing attackers to exploit the issue without needing to log in to the router.
Potential Impact and Exploitation
Successful exploitation of these vulnerabilities permits attackers to inject and execute arbitrary system commands as the root user, granting them maximum control over the device. The CVSS v4.0 score for CVE-2026-9254 is 8.7, categorizing it as a high-risk flaw. TP-Link cautions that this could compromise the router’s confidentiality, integrity, and availability, as well as the security of the network traffic passing through it.
The second vulnerability, CVE-2026-16348, affects the VPN functionality of Archer BE800 V1 routers. This flaw requires administrative access and allows attackers to inject shell metacharacters via a VPN connection, executing commands with root privileges. Although administrative access is needed, the potential damage is significant, allowing attackers to establish backdoors, steal credentials, and launch attacks on other network-connected systems. This vulnerability has a CVSS v4.0 score of 8.5.
Mitigation and Recommendations
CVE-2026-78541 is a stored command injection vulnerability in the parental control module of Archer BE3600 V1 routers. An attacker with administrative access can create a malicious profile name containing shell metacharacters, which are stored and later executed when the router processes its cloud report. This issue also holds a CVSS score of 8.5.
TP-Link recommends users download the latest firmware from their regional support sites and verify the hardware revision before proceeding with updates. It is critical to change default administrator credentials and restrict router administration to trusted devices. Organizations should disable unnecessary remote management services and monitor network logs for unusual activities.
In conclusion, addressing these vulnerabilities promptly is crucial to safeguarding network security. By applying the necessary updates and following best practices, users can protect their routers and connected devices from potential threats.
