CVE-2026-16348
8.5TP-Link · Archer BE800 v1
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an administrative user to execute arbitrary system commands via a VPN connection.
Executive summary
An authenticated command injection flaw in TP-Link Archer BE800 V1 routers could allow administrative users to gain full root-level control of the device.
Vulnerability
This is a command injection vulnerability where an attacker with administrative privileges can inject shell metacharacters through the VPN connection interface. The vulnerability requires existing administrative access to the device management interface.
Business impact
The ability to execute arbitrary commands with root privileges grants an attacker total control over the router, enabling data interception, network manipulation, or persistence. With a CVSS score of 8.5, this high-severity issue poses a critical threat to network integrity and confidentiality.
Remediation
Immediate Action: Update the firmware of the Archer BE800 v1 to version 1.4.2 Build 260708 or later as provided by the TP-Link support portal.
Proactive Monitoring: Audit administrative login logs and VPN connection logs for suspicious activity or unauthorized configuration changes.
Compensating Controls: Restrict administrative access to the router to trusted internal management networks only, preventing remote exposure of the management interface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Administrators must treat this vulnerability as critical due to the potential for root-level compromise. Apply the firmware update immediately to eliminate the command injection vector and secure the device management interface.