PT-2026-5684 · Tp Link · Archer Be230

·

CVE-2026-0631

·

Published

2026-02-02

·

Updated

2026-07-31

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions TP-Link Archer BE230 versions prior to 1.2.4 Build 20251218 rel.70420 TP-Link Archer AXE75 v1 versions prior to 1.5.6 Build 20260623
Description An OS command injection issue exists within the VPN modules of the affected devices. This flaw allows an adjacent authenticated attacker to execute arbitrary code, potentially granting full administrative control over the device. Such exploitation can lead to a severe compromise of network security, service availability, and configuration integrity. This issue is one of several distinct command injection flaws identified across different code paths.
Recommendations Update TP-Link Archer BE230 to version 1.2.4 Build 20251218 rel.70420 or later. Update TP-Link Archer AXE75 v1 to version 1.5.6 Build 20260623 or later. As a temporary mitigation, restrict access to the VPN modules to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02131
CVE-2026-0631

Affected Products

Archer Be230