logo

Multiple TP-Link OS Command Injection Vulnerabilities Let Attackers Gain Admin Control of the Device

ID: 5b1d1a97-3cb0-5683-b79c-f48dd03bc33b

STIX ID: report--5b1d1a97-3cb0-5683-b79c-f48dd03bc33b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Abinaya

...
...

TP-Link has released urgent firmware updates for Archer BE230 v1.2 devices to remediate multiple high-severity OS command injection vulnerabilities (several CVEs, CVSS ~8.5–8.6) in web, VPN, cloud communication, and configuration modules that can allow authenticated attackers to execute arbitrary root commands, gain full device control, intercept traffic, disrupt services, or pivot to other network hosts; administrators are strongly advised to apply the provided patched firmware immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.