Authenticated Command Injection Vulnerability in TP-Link Archer Router
CVE-2026-16348

8.5HIGH

Key Information:

Vendor
CVE Published:
24 August 2026

What is CVE-2026-16348?

An authenticated command injection vulnerability exists in the TP-Link Archer BE800 V1 router. With administrative access, an attacker can execute arbitrary system commands with root privileges by injecting shell metacharacters through a VPN connection. This exploitation can lead to serious security issues including the potential creation of persistent backdoors, theft of credentials, reconnaissance of the local area network (LAN), and router-assisted attacks targeting connected devices.

Affected Version(s)

Archer BE800 v1 0 < 1.4.2 Build 260708

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sean Lagan, UploadSecurity
.