Command Injection Vulnerability in Archer VPN Connection Service
CVE-2026-22225
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 2 February 2026
What is CVE-2026-22225?
A command injection vulnerability exists in the VPN Connection Service of the TP-Link Archer BE230 device. This flaw can be exploited post-authentication, enabling attackers to take full administrative control over the device. The exploitation of this vulnerability could lead to significant risks, including compromising configuration integrity, undermining network security, and causing disruptions in service availability. Immediate action is advised for users operating on affected firmware versions to ensure their devices remain secure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Archer BE230 v1.2 0 < 1.2.4 Build 20251218 rel.70420
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
