Rewterz

Critical isolated-vm JavaScript Flaw Enables Sandbox Escape

August 24, 2026
Rewterz

Zyxel Patches Command Injection Flaw in 18 Access Points

August 25, 2026

TP-Link Archer Vulnerabilities Allow Command Injection Attacks

Severity

High

Analysis Summary

TP-Link has disclosed three high-severity command injection vulnerabilities affecting the Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. Tracked as CVE-2026-9254, CVE-2026-16348, and CVE-2026-78541, the flaws could allow attackers on the local network or authenticated administrators to execute arbitrary operating-system commands with root privileges. Successful exploitation could result in complete router compromise, including unauthorized access to sensitive information, modification of device configurations, disruption of services, and potential attacks against other systems connected to the same network. TP-Link’s security advisory was last updated on August 24, 2026, and firmware updates are available for all affected products.

CVE-2026-9254 is the most concerning of the three vulnerabilities because it is an unauthenticated OS command injection flaw in the parental-control functionality of the Archer BE800 V1, BE3600 V1, and AX75 V1. The vulnerability results from insufficient filtering and neutralization of special characters in certain parameters, allowing a nearby attacker to inject malicious commands without authenticating to the router. The injected commands execute with root-level privileges, potentially giving the attacker complete control over the device and the network traffic passing through it. The vulnerability has a CVSS v4.0 score of and is rated High.

CVE-2026-16348 affects the VPN functionality of the Archer BE800 V1 and requires valid administrative credentials, making it an authenticated command injection vulnerability. An attacker with administrative access could inject shell metacharacters through a VPN connection and execute arbitrary commands as root. Meanwhile, CVE-2026-78541 affects the parental-control module of the Archer BE3600 V1 and is a stored command injection flaw. An authenticated administrator can create a malicious profile name containing shell metacharacters, which is stored and later processed when the router generates its daily cloud report, potentially resulting in delayed arbitrary command execution. Both vulnerabilities have a CVSS v4.0 score of 8.5. If exploited, these flaws could enable persistence, credential theft, local-network reconnaissance, and attacks against connected systems.

TP-Link has released fixed firmware for all affected devices and recommends users update promptly. For CVE-2026-9254, the required versions are Archer BE800 1.4.2 Build 260708, BE3600 1.2.6 Build 20260617, and AX75 1.1.6 Build 260716. CVE-2026-16348 is fixed in Archer BE800 1.4.2 Build 260708, while CVE-2026-78541 is fixed in Archer BE3600 1.2.6 Build 20260617. Users should verify their router’s hardware revision and install firmware from the appropriate TP-Link regional support page, replace default administrator credentials, restrict administrative access to trusted devices, disable unnecessary remote-management services, and monitor router and network logs for unexpected configuration changes, suspicious activity, or unusual outbound connections.

Impact

  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-9254

  • CVE-2026-16348

  • CVE-2026-78541

Remediation

  • Update all affected TP-Link Archer routers to the latest fixed firmware:Archer BE800 V1: 1.4.2 Build 260708, Archer BE3600 V1: 1.2.6 Build 20260617, and Archer AX75 V1: 1.1.6 Build 260716
  • Verify the router’s hardware revision before installing firmware.
  • Replace default or weak administrator credentials with strong, unique passwords.
  • Restrict router administration to trusted devices and networks only.
  • Disable unnecessary remote-management and VPN services if they are not required.
  • Limit administrative access to authorized personnel and apply least-privilege access controls.
  • Monitor router and network logs for unexpected configuration changes, suspicious commands, or unusual outbound connections.
  • Review connected devices for signs of unauthorized access or lateral movement following potential exploitation.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.