CVE-2026-9254
largeUnauthenticated OS command injection in TP-Link Archer BE800/BE3600/AX75 routers
CVE-2026-9254 is an unauthenticated OS command injection (CWE-78) in the parental control functionality of TP-Link Archer BE800 V1, BE3600 V1, and AX75 V1 routers, caused by improper filtering and neutralization of special characters in certain parameters. An attacker already positioned on the local network can supply crafted values in these parameters without any credentials, injecting arbitrary operating-system commands that execute with root privileges. Successful exploitation yields complete compromise of the router, with high impact on the confidentiality, integrity, and availability of the device and of the network traffic passing through it. All owners of these three V1 hardware versions are affected, although the adjacent-network attack vector means internet-facing exposure alone is not sufficient — the attacker must have LAN/Wi-Fi access. As of this writing there is no public proof of concept, the flaw is not in CISA's KEV, and EPSS estimates a 2.3% probability of exploitation within 30 days (83rd percentile).
What to do: Verify the hardware version on the device label (only V1 units are affected) and update each router to the latest firmware available on TP-Link's support/download page for that model; no specific fixed firmware version is stated in the available data. Until patched, restrict which LAN segments and devices (especially guest and IoT networks) can reach the router's management interface, since exploitation requires adjacent-network access. No public PoC exists yet, so patch promptly before exploit details emerge.
| TP-Link Archer BE800 | V1 |
| TP-Link Archer BE3600 | V1 |
| TP-Link Archer AX75 | V1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.