CVE-2026-9254
8.7TP-Link · Archer BE800 V1, BE3600 V1, AX75 V1
An unauthenticated OS command injection vulnerability in the parental control functionality of multiple TP-Link Archer routers allows remote attackers to execute arbitrary system commands.
Executive summary
A critical OS command injection vulnerability in the parental control feature of specific TP-Link Archer routers permits unauthenticated remote code execution.
Vulnerability
This is an OS command injection flaw (CWE-78) triggered by improper neutralization of special characters within the parental control module. The vulnerability is exploitable by an unauthenticated attacker with adjacent network access.
Business impact
A successful exploit grants an attacker full control over the affected network device. This may lead to complete compromise of the local network, unauthorized data access, and the potential to intercept or redirect traffic, resulting in significant security and operational risk. The CVSS score of 8.7 highlights the severity of this remote, unauthenticated access vector.
Remediation
Immediate Action: Update the firmware of all affected Archer devices to the versions specified above or the latest available release from the TP-Link support portal.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from router management interfaces and review system logs for suspicious command execution patterns.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and disable remote management features if they are not strictly required.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
Given the ease of exploitation and the critical impact on network integrity, administrators must prioritize patching these devices immediately. Ensure that firmware updates are applied across all affected units to mitigate the risk of remote command injection.