Authenticated Command Injection Vulnerability in TP-Link Archer Router
CVE-2026-16348
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 24 August 2026
Badges
What is CVE-2026-16348?
An authenticated command injection vulnerability exists in the TP-Link Archer BE800 V1 router. With administrative access, an attacker can execute arbitrary system commands with root privileges by injecting shell metacharacters through a VPN connection. This exploitation can lead to serious security issues including the potential creation of persistent backdoors, theft of credentials, reconnaissance of the local area network (LAN), and router-assisted attacks targeting connected devices.
Affected Version(s)
Archer BE800 v1 0 < 1.4.2 Build 260708
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
