CVE-2026-9254
Received Received - Intake

Unauthenticated OS Command Injection in TP-Link Archer BE800 V1

Vulnerability report for CVE-2026-9254, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: TPLink

Description

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
tp-link archer_be3600 v2.6_1.1.4_build_20260119
tp-link archer_be3600 v2.6_1.1.3_build_20251120
tp-link archer_be3600 v2.60_1.0.4_build_20250519
tp-link archer_ax75 v1.1.6_build_260716
tp-link archer_be800 v1.4.2_build_260708
tp-link archer_be800 v1
tp-link be3600 v1
tp-link ax75 v1
tp-link archer_be3600 v1
tp-link archer_ax75 v1
tp-link archer_be3600 From 1.0.4 (inc) to 1.4.2 (exc)
tp-link archer_ax75 From 1.1.1 (inc) to 1.1.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-9254 is an unauthenticated OS command injection vulnerability in TP-Link Archer BE800 V1, BE3600 V1, and AX75 V1 routers. It exists in the parental control functionality due to improper filtering of special characters in certain parameters. A LAN-based attacker can inject and execute arbitrary commands with root privileges, potentially compromising the entire device.

Detection Guidance

Detection requires checking if your device is running vulnerable firmware versions. For Archer BE800 V1, verify if firmware is below 1.4.2 Build 260708. For BE3600 V1, check if firmware is below 1.2.6 Build 20260617. For AX75 V1, confirm firmware is below 1.1.6 Build 260716. Use the device admin panel or TP-Link's official tools to inspect firmware versions.

Impact Analysis

Exploitation may result in complete device compromise, allowing attackers to gain root access. This could lead to loss of confidentiality, integrity, and availability of the device and network traffic. Attackers might intercept sensitive data, disrupt network operations, or use the device as a foothold for further attacks within the local network.

Compliance Impact

This vulnerability could lead to unauthorized access and control of network devices, potentially exposing sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) due to risks of data breaches, unauthorized access, and compromised confidentiality and integrity of network traffic.

Mitigation Strategies

Immediately update the firmware of affected devices to the latest versions provided by TP-Link. Download firmware only from official regional TP-Link websites. Avoid using third-party firmware. Ensure wired connections during updates to prevent interruptions. Monitor device behavior for signs of compromise.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9254. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart