CVE-2026-16348
Received Received - Intake

Authenticated Command Injection in TP-Link Archer BE800 V1

Vulnerability report for CVE-2026-16348, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: TPLink

Description

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.Β  Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
tp-link archer_be800 to 1.4.2 (exc)
tp-link archer_be3600 v1
tp-link archer_ax75 v1
tp-link archer_be800 v1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated command injection vulnerability in TP-Link Archer BE800 V1 routers. It allows an attacker with admin access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized VPN configurations or suspicious command execution logs on TP-Link Archer BE800 V1 devices. Review VPN connection logs for unusual shell metacharacters or unexpected command sequences. Inspect system logs for root-level command executions originating from VPN-related processes.

Impact Analysis

Exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.

Compliance Impact

This vulnerability could lead to unauthorized access, data exfiltration, and persistent backdoors, which may violate data protection requirements under GDPR and HIPAA. Compromise of the router could expose sensitive network traffic and connected devices, potentially resulting in non-compliance with confidentiality and integrity controls mandated by these regulations.

Mitigation Strategies

Immediately update the TP-Link Archer BE800 V1 firmware to the latest version. Disable VPN access if not required. Restrict administrative access to trusted users only. Monitor network traffic for unusual outbound connections or data exfiltration attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16348. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart