Authenticated Command Injection Vulnerability in TP-Link Archer Router
CVE-2026-16348
8.5HIGH
What is CVE-2026-16348?
An authenticated command injection vulnerability exists in the TP-Link Archer BE800 V1 router. With administrative access, an attacker can execute arbitrary system commands with root privileges by injecting shell metacharacters through a VPN connection. This exploitation can lead to serious security issues including the potential creation of persistent backdoors, theft of credentials, reconnaissance of the local area network (LAN), and router-assisted attacks targeting connected devices.
Affected Version(s)
Archer BE800 v1 0 < 1.4.2 Build 260708
