CVE-2026-78541
8.5TP-Link · Archer BE3600 v1
A stored OS command injection vulnerability in the parental control module of the TP-Link Archer BE3600 v1 allows an authenticated administrator to execute arbitrary commands on the underlying system.
Executive summary
An authenticated OS command injection vulnerability in the TP-Link Archer BE3600 v1 enables an attacker with administrative access to execute arbitrary system commands.
Vulnerability
This is an OS command injection flaw (CWE-78) within the parent control module. It requires the attacker to possess high privileges (authenticated as an administrator) to successfully trigger the injection.
Business impact
While the requirement for administrative authentication limits the attack surface, a successful exploit allows an attacker to escalate their control to the underlying operating system. This could lead to persistence, network-wide data interception, or the deployment of malicious firmware. The CVSS score of 8.5 reflects the high impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update the firmware of the Archer BE3600 v1 to version 1.2.6 Build 20260617 or newer.
Proactive Monitoring: Audit administrative login logs for unauthorized or suspicious activity, and monitor for unexpected changes to device configuration or system files.
Compensating Controls: Implement strict access control for the administrative web interface and ensure that only authorized personnel have credentials for the device.
Exploitation status
Public Exploit Available: No confirmed public exploit (Metasploit or ExploitDB) is currently available.
Analyst recommendation
Although this vulnerability requires administrative access, it remains a critical security flaw that could be used for lateral movement or persistence. Administrators should apply the provided firmware update as part of standard maintenance cycles to ensure device security.