CVE-2026-78541
largeAuthenticated OS Command Injection in TP-Link Archer BE3600 V1 Parent Controls
CVE-2026-78541 is a stored OS command injection flaw (CWE-78) in the parental-control module of the TP-Link Archer BE3600 V1 router. An attacker who already has adjacent (same LAN/Wi-Fi) access and administrative privileges can save a parental-control profile name containing shell metacharacters; when the router later generates its daily cloud report, the stored profile name is passed to the operating system without sanitization, causing attacker-supplied commands to execute. Successful exploitation yields arbitrary command execution on the router, with high impact to the device's confidentiality, integrity, and availability, effectively enabling full device compromise. Only TP-Link Archer BE3600 V1 units are identified as affected, and exploitation requires administrative credentials from an adjacent network, which limits who can realistically exploit it. As of now there is no public proof-of-concept, the CVE is not listed in CISA's KEV, and EPSS estimates roughly a 1% probability of exploitation within 30 days, though the CVSS 4.0 base score of 8.5 (High) reflects the potential for full device takeover.
What to do: Check TP-Link's support/download page for the Archer BE3600 V1 and install patched firmware as soon as a fixed release is published (no fixed version is specified in the advisory data). Until then, restrict the router's administrative interface to trusted LAN/Wi-Fi clients, use strong unique admin credentials, and avoid creating parental-control profile names containing shell metacharacters such as ; | $ ` or &; disable the daily cloud report feature if the interface permits.
| TP-Link Archer BE3600 V1 router (parental-control module) | V1 hardware; affected firmware range and fixed release are not specified in the source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.