An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.






Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.

Project Subscriptions

Vendors Products
Tp-link Subscribe
Archer Ax75 V1 Subscribe
Archer Be3600 V1 Subscribe
Archer Be800 V1 Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Ax75 V1
Tp-link archer Be3600 V1
Tp-link archer Be800 V1
Vendors & Products Tp-link
Tp-link archer Ax75 V1
Tp-link archer Be3600 V1
Tp-link archer Be800 V1

Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
Title Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-24T17:47:29.558Z

Reserved: 2026-05-21T20:23:27.422Z

Link: CVE-2026-9254

cve-icon Vulnrichment

Updated: 2026-08-24T17:47:26.454Z

cve-icon NVD

Status : Received

Published: 2026-08-24T18:17:34.973

Modified: 2026-08-24T18:17:34.973

Link: CVE-2026-9254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:09:59Z

Weaknesses