logo

TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution

ID: 0b448051-fe70-5d3f-9ee8-35bed6b218ce

STIX ID: report--0b448051-fe70-5d3f-9ee8-35bed6b218ce

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Tamilselvan

...
...

TP-Link disclosed three high-severity command-injection vulnerabilities in Archer BE800 V1, BE3600 V1, and AX75 V1 routers (CVE-2026-9254, CVE-2026-16348, CVE-2026-78541) that can allow attackers to execute arbitrary OS commands as root; one is an unauthenticated LAN-based flaw and others require administrative access or are stored injections. TP-Link released firmware updates for each affected model and recommends verifying hardware versions, updating firmware from official portals, reviewing admin accounts and parental-control profiles, disabling unnecessary remote administration, and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.