Command Injection Vulnerability in TP-Link Archer BE230 Router
CVE-2026-22226
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 2 February 2026
Badges
What is CVE-2026-22226?
CVE-2026-22226 is a command injection vulnerability present in TP-Link's Archer BE230 v1.2 and Archer AX73 v2 routers. This vulnerability specifically affects the VPN server configuration module, where an authenticated admin user may unknowingly trigger the execution of arbitrary commands on the device. Successful exploitation of this flaw could allow an attacker to gain complete administrative control over the affected router, leading to severe consequences for network security and device integrity. The issue is particularly critical due to the router's role in managing and securing network traffic; a compromised router can expose sensitive information, disrupt services, and allow unauthorized access to internal networks.
The affected firmware versions are Archer BE230 v1.2 prior to 1.2.4 Build 20251218 and Archer AX73 v2 prior to 1.3.1 Build 20260430. As this vulnerability represents one of several command injection issues identified in TP-Link routers, organizations utilizing these devices must remain vigilant and proactive in implementing security measures to mitigate potential exploitation.
Potential impact of CVE-2026-22226
-
Full Administrative Access: Attackers exploiting this vulnerability can achieve complete control over the affected router. This level of access enables unauthorized configuration changes, surveillance of network traffic, and potential interception of sensitive data transmitted over the network.
-
Network Security Compromise: The exploitation could lead to widespread vulnerabilities across the connected devices and systems. An attacker could pivot from the compromised router to other devices on the network, facilitating lateral movement and further attacks on corporate infrastructure.
-
Service Disruption: By gaining administrative control, attackers may alter or disable vital services running on the router, resulting in significant downtime and operational disruptions for organizations reliant on internet connectivity and network services. This can also affect end-users who depend on the stability of network resources for business and personal use.
Affected Version(s)
Archer AX73 v2 0 < 1.3.1 Build 20260430
Archer BE230 v1.2 0 < 1.2.4 Build 20251218 rel.70420
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
