PT-2026-80985 · Tp Link · Archer Be3600 V1+2

·

CVE-2026-9254

·

Published

2026-08-24

·

Updated

2026-08-25

CVSS v4.0

8.7

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Archer BE800 V1 (affected versions not specified) Archer BE3600 V1 (affected versions not specified) Archer AX75 V1 (affected versions not specified)
Description An unauthenticated OS command injection exists in the parental control functionality. This issue occurs because the system fails to properly filter and neutralize special characters in certain parameters, allowing a LAN-based attacker to inject and execute arbitrary commands with root privileges. Successful exploitation can lead to complete device compromise, impacting the confidentiality, integrity, and availability of the device and network traffic.
Recommendations Update the firmware for Archer BE800 V1. Update the firmware for Archer BE3600 V1. Update the firmware for Archer AX75 V1.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9254

Affected Products

Archer Axe75 V1
Archer Be3600 V1
Archer Be800 V1