Command Injection Vulnerability in TP-Link Archer BE230 Router
CVE-2026-22226

8.5HIGH

Key Information:

Vendor
CVE Published:
2 February 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-22226?

CVE-2026-22226 is a command injection vulnerability present in TP-Link's Archer BE230 v1.2 and Archer AX73 v2 routers. This vulnerability specifically affects the VPN server configuration module, where an authenticated admin user may unknowingly trigger the execution of arbitrary commands on the device. Successful exploitation of this flaw could allow an attacker to gain complete administrative control over the affected router, leading to severe consequences for network security and device integrity. The issue is particularly critical due to the router's role in managing and securing network traffic; a compromised router can expose sensitive information, disrupt services, and allow unauthorized access to internal networks.

The affected firmware versions are Archer BE230 v1.2 prior to 1.2.4 Build 20251218 and Archer AX73 v2 prior to 1.3.1 Build 20260430. As this vulnerability represents one of several command injection issues identified in TP-Link routers, organizations utilizing these devices must remain vigilant and proactive in implementing security measures to mitigate potential exploitation.

Potential impact of CVE-2026-22226

  1. Full Administrative Access: Attackers exploiting this vulnerability can achieve complete control over the affected router. This level of access enables unauthorized configuration changes, surveillance of network traffic, and potential interception of sensitive data transmitted over the network.

  2. Network Security Compromise: The exploitation could lead to widespread vulnerabilities across the connected devices and systems. An attacker could pivot from the compromised router to other devices on the network, facilitating lateral movement and further attacks on corporate infrastructure.

  3. Service Disruption: By gaining administrative control, attackers may alter or disable vital services running on the router, resulting in significant downtime and operational disruptions for organizations reliant on internet connectivity and network services. This can also affect end-users who depend on the stability of network resources for business and personal use.

Affected Version(s)

Archer AX73 v2 0 < 1.3.1 Build 20260430

Archer BE230 v1.2 0 < 1.2.4 Build 20251218 rel.70420

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

jro
.