ZeroHour

CVE-2026-9254

large

Unauthenticated OS command injection in TP-Link Archer BE800/BE3600/AX75 routers

CVSS 4.0
8.7 high
EPSS
2%p83
Published
()
Modified
AI analysis

CVE-2026-9254 is an unauthenticated OS command injection (CWE-78) in the parental control functionality of TP-Link Archer BE800 V1, BE3600 V1, and AX75 V1 routers, caused by improper filtering and neutralization of special characters in certain parameters. An attacker already positioned on the local network can supply crafted values in these parameters without any credentials, injecting arbitrary operating-system commands that execute with root privileges. Successful exploitation yields complete compromise of the router, with high impact on the confidentiality, integrity, and availability of the device and of the network traffic passing through it. All owners of these three V1 hardware versions are affected, although the adjacent-network attack vector means internet-facing exposure alone is not sufficient — the attacker must have LAN/Wi-Fi access. As of this writing there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates a 2.3% probability of exploitation within 30 days (83rd percentile).

What to do: Verify the hardware version on the device label (only V1 units are affected) and update each router to the latest firmware available on TP-Link's support/download page for that model; no specific fixed firmware version is stated in the available data. Until patched, restrict which LAN segments and devices (especially guest and IoT networks) can reach the router's management interface, since exploitation requires adjacent-network access. No public PoC exists yet, so patch promptly before exploit details emerge.

Affected
TP-Link Archer BE800V1
TP-Link Archer BE3600V1
TP-Link Archer AX75V1
Estimated exposure
largeroughly 10^5–10^6 consumer router units in use worldwide (three widely sold retail SKUs; no official per-model install base published) — TP-Link is among the highest-volume consumer Wi-Fi router brands and these three models have been sold through retail channels over multiple years, making an install base in the hundreds of thousands to low millions plausible, though the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.

Weakness
CWE-78
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.