CVE-2026-9254
Received
Received - Intake
Unauthenticated OS Command Injection in TP-Link Archer BE800 V1
Vulnerability report for CVE-2026-9254, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-24
Last updated on: 2026-08-24
Assigner: TPLink
Description
Description
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.
Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tp-link | archer_be3600 | v2.6_1.1.4_build_20260119 |
| tp-link | archer_be3600 | v2.6_1.1.3_build_20251120 |
| tp-link | archer_be3600 | v2.60_1.0.4_build_20250519 |
| tp-link | archer_ax75 | v1.1.6_build_260716 |
| tp-link | archer_be800 | v1.4.2_build_260708 |
| tp-link | archer_be800 | v1 |
| tp-link | be3600 | v1 |
| tp-link | ax75 | v1 |
| tp-link | archer_be3600 | v1 |
| tp-link | archer_ax75 | v1 |
| tp-link | archer_be3600 | From 1.0.4 (inc) to 1.4.2 (exc) |
| tp-link | archer_ax75 | From 1.1.1 (inc) to 1.1.6 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |