PT-2026-5684 · Tp Link · Archer Be230
CVSS v4.0
8.5
High
| Vector | AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
TP-Link Archer BE230 versions prior to 1.2.4 Build 20251218 rel.70420
TP-Link Archer AXE75 v1 versions prior to 1.5.6 Build 20260623
Description
An OS command injection issue exists within the VPN modules of the affected devices. This flaw allows an adjacent authenticated attacker to execute arbitrary code, potentially granting full administrative control over the device. Such exploitation can lead to a severe compromise of network security, service availability, and configuration integrity. This issue is one of several distinct command injection flaws identified across different code paths.
Recommendations
Update TP-Link Archer BE230 to version 1.2.4 Build 20251218 rel.70420 or later.
Update TP-Link Archer AXE75 v1 to version 1.5.6 Build 20260623 or later.
As a temporary mitigation, restrict access to the VPN modules to minimize the risk of exploitation.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archer Be230