PT-2026-80993 · Tp Link · Archer Be3600
CVE-2026-78541
·
Published
2026-08-24
·
Updated
2026-08-25
CVSS v4.0
8.5
High
| Vector | AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
TP-Link Archer BE3600 version V1
Description
A stored OS command injection exists in the parent-control module. An authenticated adjacent attacker with administrative access can store a crafted profile name containing shell metacharacters. This input is processed unsafely during the daily cloud report generation process, potentially leading to arbitrary command execution on the device, which impacts confidentiality, integrity, and availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archer Be3600