ZeroHour

CVE-2026-16348

large

Authenticated Command Injection in TP-Link Archer BE800 V1 Routers

CVSS 4.0
8.5 high
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-16348 is an authenticated command injection flaw (CWE-78) in the VPN connection handling of the TP-Link Archer BE800 V1 router, in which shell metacharacters submitted in VPN-related input are passed to a system shell without sanitization. To trigger it, an attacker needs administrative access (CVSS 4.0 privilege requirement: high) on the adjacent network, e.g., via the LAN or a VPN session, and injects metacharacters into a VPN connection field; no user interaction is required. Because the injected commands run with root privileges, an attacker can install persistent backdoors, steal credentials, perform reconnaissance of the LAN, and launch attacks against devices connected to the router. Affected parties are owners/administrators of TP-Link Archer BE800 V1 (hardware version 1) routers, particularly those with the VPN feature enabled; the data does not specify affected firmware version ranges. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates a 0.9% chance of exploitation within 30 days (58th percentile).

What to do: Administrators of Archer BE800 V1 routers should check their hardware version, apply TP-Link's fixed firmware as soon as it is published (no fixed version is specified in the available data), and restrict the admin interface to trusted LAN segments while limiting VPN access to necessary users. Review VPN configuration pages and accounts for unexpected entries or unknown admin credentials, and if compromise is suspected, update firmware, rotate all router and VPN credentials, and consider a factory reset. Monitor TP-Link's advisories for the patched release and any updates to exploitation status.

Affected
TP-Link Archer BE800V1 (hardware version 1); affected firmware ranges not specified in available data
Estimated exposure
largelikely on the order of tens of thousands of units worldwide (single premium Wi-Fi 7 router SKU; the subset with the VPN feature in active use is smaller) — The Archer BE800 is a single high-end (approx. $600) flagship Wi-Fi 7 model with early-adoption-only deployment volumes, and exploitation additionally requires administrative access and use of the VPN feature, so no public install-base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection. Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.

Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.