OS Command Injection Vulnerability in Archer BE800, BE3600, and AX75 Routers by TP-Link
CVE-2026-9254
8.7HIGH
Key Information:
- Vendor
Tp-link Systems Inc.
- Vendor
- CVE Published:
- 24 August 2026
What is CVE-2026-9254?
An OS command injection vulnerability has been identified in the parental control feature of select Archer router models. Due to improper filtering of input parameters, an unauthenticated attacker on the local area network can execute arbitrary commands with root privileges. This exploitation may lead to complete takeover of the affected devices, thereby compromising the confidentiality, integrity, and availability of both the device and the network it operates within.
Affected Version(s)
Archer AX75 V1 0 < 1.1.6 Build 260716
Archer BE3600 V1 0 < 1.2.6 Build 20260617
Archer BE800 V1 0 < 1.4.2 Build 260708
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sean Lagan, UploadSecurity
Sungmin Kang (rauzn), JeroScope
Sergio Medeiros (grumpz)
