Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical TP-Link Archer Flaws Let Attackers Inject Commands
August 25, 2026
Palo Alto GlobalProtect Critical Flaws Let Attackers Execute Code
August 25, 2026
Microsoft Teams Update Lets Admins Auto-Block Meeting Bots
August 24, 2026
Home/CyberSecurity News/Critical TP-Link Archer Flaws Let Attackers Inject Commands
CyberSecurity News

Critical TP-Link Archer Flaws Let Attackers Inject Commands

Key Takeaways TP-Link has addressed three high-severity command injection vulnerabilities across multiple Archer router models. The flaws, including one unauthenticated vulnerability, could allow...

Marcus Rodriguez
Marcus Rodriguez
August 25, 2026 3 Min Read
2 0

Key Takeaways

  • TP-Link has addressed three high-severity command injection vulnerabilities across multiple Archer router models.
  • The flaws, including one unauthenticated vulnerability, could allow attackers to execute arbitrary commands with root privileges.
  • Affected models include Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1.
  • Firmware updates are available, and users are strongly advised to apply them immediately.

TP-Link has issued a critical security advisory concerning three high-severity command injection vulnerabilities impacting several models in its Archer router series. These security flaws, if exploited, could grant nearby attackers root-level access, leading to complete device compromise and potential further attacks on devices within the local network.

Table Of Content

  • Key Takeaways
  • Unauthenticated Command Injection in Parental Controls (CVE-2026-9254)
  • Authenticated Command Injection in VPN Functionality (CVE-2026-16348)
  • Stored Command Injection via Parental-Control Profile Names (CVE-2026-78541)
  • What You Should Do

The vulnerabilities, detailed in a security advisory updated on August 24, 2026, are identified as CVE-2026-9254, CVE-2026-16348, and CVE-2026-78541. TP-Link has promptly released firmware updates for all affected products and is urging customers to install these patches without delay.

Unauthenticated Command Injection in Parental Controls (CVE-2026-9254)

The most severe of the disclosed issues is CVE-2026-9254, an unauthenticated operating-system command-injection vulnerability present in the parental control function of Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 devices. This flaw stems from inadequate filtering and neutralization of special characters within specific parameters.

An attacker operating on the local network could exploit this vulnerability without needing to authenticate or log into the router. Successful exploitation would enable the injection and execution of arbitrary system commands as the root user, granting the attacker the highest possible privilege level on the device. This issue has been assigned a CVSS v4.0 score of 8.7, categorizing it as High severity. TP-Link warns that exploitation could severely impact the confidentiality, integrity, and availability of both the router and all network traffic.

Authenticated Command Injection in VPN Functionality (CVE-2026-16348)

The second vulnerability, CVE-2026-16348, affects the VPN connection feature specifically on Archer BE800 V1 routers. This is an authenticated command injection flaw, meaning it requires administrative access for exploitation. An attacker with valid administrator credentials could inject shell metacharacters through a VPN connection, subsequently executing commands with root privileges. Despite the requirement for prior authentication, the potential impact remains significant.

Successful attacks could allow threat actors to establish persistent backdoors, steal sensitive credentials, perform reconnaissance on the local network, and leverage the compromised router to target other connected systems. CVE-2026-16348 carries a CVSS v4.0 score of 8.5, also rated as High severity.

Stored Command Injection via Parental-Control Profile Names (CVE-2026-78541)

The third identified flaw, CVE-2026-78541, is a stored command injection vulnerability found in the parental control module of Archer BE3600 V1 routers. An authenticated attacker possessing administrative access can craft a malicious profile name containing shell metacharacters. This harmful input is then stored on the device and may be processed unsafely at a later stage, specifically when the router generates its daily cloud report. This delayed execution path can result in arbitrary commands being run on the router.

TP-Link assigned this vulnerability a CVSS v4.0 score of 8.5. The following table summarizes the vulnerabilities and corresponding fixed firmware versions:

CVE Vulnerability Affected Product Fixed Firmware CVSS
CVE-2026-9254 Unauthenticated OS command injection in parental controls Archer BE800, BE3600, AX75 BE800: 1.4.2 Build 260708; BE3600: 1.2.6 Build 20260617; AX75: 1.1.6 Build 260716 8.7
CVE-2026-16348 Authenticated command injection in VPN functionality Archer BE800 1.4.2 Build 260708 8.5
CVE-2026-78541 Stored OS command injection via parental-control profile names Archer BE3600 1.2.6 Build 20260617 8.5

What You Should Do

  • Immediately download and install the newest firmware updates from TP-Link’s official regional support pages for your specific router model.
  • Before updating, verify the installed hardware revision of your router to ensure you are applying the correct firmware.
  • Change any default administrator credentials on your router to strong, unique passwords.
  • Restrict router administration access to only trusted devices within your network.
  • Disable any remote management services that are not strictly necessary.
  • Regularly monitor network logs for any unusual configuration changes or unexpected outbound traffic patterns.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Palo Alto GlobalProtect Critical Flaws Let Attackers Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Kimsuky Uses AI-Generated Chrome Extension to Steal Gmail Data
August 24, 2026
768 Leaked Corporate AWS Keys Grant Full Administrator Access
August 24, 2026
ReliaQuest Warns of Phishing Attacks Impersonating Staff for SSO Credentials
August 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us