CVE-2026-16348
largeAuthenticated Command Injection in TP-Link Archer BE800 V1 Routers
CVE-2026-16348 is an authenticated command injection flaw (CWE-78) in the VPN connection handling of the TP-Link Archer BE800 V1 router, in which shell metacharacters submitted in VPN-related input are passed to a system shell without sanitization. To trigger it, an attacker needs administrative access (CVSS 4.0 privilege requirement: high) on the adjacent network, e.g., via the LAN or a VPN session, and injects metacharacters into a VPN connection field; no user interaction is required. Because the injected commands run with root privileges, an attacker can install persistent backdoors, steal credentials, perform reconnaissance of the LAN, and launch attacks against devices connected to the router. Affected parties are owners/administrators of TP-Link Archer BE800 V1 (hardware version 1) routers, particularly those with the VPN feature enabled; the data does not specify affected firmware version ranges. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates a 0.9% chance of exploitation within 30 days (58th percentile).
What to do: Administrators of Archer BE800 V1 routers should check their hardware version, apply TP-Link's fixed firmware as soon as it is published (no fixed version is specified in the available data), and restrict the admin interface to trusted LAN segments while limiting VPN access to necessary users. Review VPN configuration pages and accounts for unexpected entries or unknown admin credentials, and if compromise is suspected, update firmware, rotate all router and VPN credentials, and consider a factory reset. Monitor TP-Link's advisories for the patched release and any updates to exploitation status.
| TP-Link Archer BE800 | V1 (hardware version 1); affected firmware ranges not specified in available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection. Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.