Severity
High
Analysis Summary
TP-Link has disclosed three high-severity command injection vulnerabilities affecting the Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. Tracked as CVE-2026-9254, CVE-2026-16348, and CVE-2026-78541, the flaws could allow attackers on the local network or authenticated administrators to execute arbitrary operating-system commands with root privileges. Successful exploitation could result in complete router compromise, including unauthorized access to sensitive information, modification of device configurations, disruption of services, and potential attacks against other systems connected to the same network. TP-Link’s security advisory was last updated on August 24, 2026, and firmware updates are available for all affected products.
CVE-2026-9254 is the most concerning of the three vulnerabilities because it is an unauthenticated OS command injection flaw in the parental-control functionality of the Archer BE800 V1, BE3600 V1, and AX75 V1. The vulnerability results from insufficient filtering and neutralization of special characters in certain parameters, allowing a nearby attacker to inject malicious commands without authenticating to the router. The injected commands execute with root-level privileges, potentially giving the attacker complete control over the device and the network traffic passing through it. The vulnerability has a CVSS v4.0 score of and is rated High.
CVE-2026-16348 affects the VPN functionality of the Archer BE800 V1 and requires valid administrative credentials, making it an authenticated command injection vulnerability. An attacker with administrative access could inject shell metacharacters through a VPN connection and execute arbitrary commands as root. Meanwhile, CVE-2026-78541 affects the parental-control module of the Archer BE3600 V1 and is a stored command injection flaw. An authenticated administrator can create a malicious profile name containing shell metacharacters, which is stored and later processed when the router generates its daily cloud report, potentially resulting in delayed arbitrary command execution. Both vulnerabilities have a CVSS v4.0 score of 8.5. If exploited, these flaws could enable persistence, credential theft, local-network reconnaissance, and attacks against connected systems.
TP-Link has released fixed firmware for all affected devices and recommends users update promptly. For CVE-2026-9254, the required versions are Archer BE800 1.4.2 Build 260708, BE3600 1.2.6 Build 20260617, and AX75 1.1.6 Build 260716. CVE-2026-16348 is fixed in Archer BE800 1.4.2 Build 260708, while CVE-2026-78541 is fixed in Archer BE3600 1.2.6 Build 20260617. Users should verify their router’s hardware revision and install firmware from the appropriate TP-Link regional support page, replace default administrator credentials, restrict administrative access to trusted devices, disable unnecessary remote-management services, and monitor router and network logs for unexpected configuration changes, suspicious activity, or unusual outbound connections.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2026-9254
CVE-2026-16348
CVE-2026-78541
Remediation
- Update all affected TP-Link Archer routers to the latest fixed firmware:Archer BE800 V1: 1.4.2 Build 260708, Archer BE3600 V1: 1.2.6 Build 20260617, and Archer AX75 V1: 1.1.6 Build 260716
- Verify the router’s hardware revision before installing firmware.
- Replace default or weak administrator credentials with strong, unique passwords.
- Restrict router administration to trusted devices and networks only.
- Disable unnecessary remote-management and VPN services if they are not required.
- Limit administrative access to authorized personnel and apply least-privilege access controls.
- Monitor router and network logs for unexpected configuration changes, suspicious commands, or unusual outbound connections.
- Review connected devices for signs of unauthorized access or lateral movement following potential exploitation.

