OS Command Injection Vulnerability in Archer BE800, BE3600, and AX75 Routers by TP-Link
CVE-2026-9254

8.7HIGH

What is CVE-2026-9254?

An OS command injection vulnerability has been identified in the parental control feature of select Archer router models. Due to improper filtering of input parameters, an unauthenticated attacker on the local area network can execute arbitrary commands with root privileges. This exploitation may lead to complete takeover of the affected devices, thereby compromising the confidentiality, integrity, and availability of both the device and the network it operates within.

Affected Version(s)

Archer AX75 V1 0 < 1.1.6 Build 260716

Archer BE3600 V1 0 < 1.2.6 Build 20260617

Archer BE800 V1 0 < 1.4.2 Build 260708

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sean Lagan, UploadSecurity
Sungmin Kang (rauzn), JeroScope
Sergio Medeiros (grumpz)
.