CVE-2026-9254: Unauthenticated OS Command Injection Hits TP-Link Archer
ID: aba1afc2-0db6-5ab7-823c-042f551fdb1e
STIX ID: report--aba1afc2-0db6-5ab7-823c-042f551fdb1e
Feed Name: securityonline.info
Threat Score
TP-Link released patches for three severe command-injection vulnerabilities affecting Archer BE800 v1, BE3600 v1, and AX75 v1 (CVE-2026-9254, CVE-2026-16348, CVE-2026-78541). The most critical is an unauthenticated OS command injection in the parental control module that can allow local attackers to execute commands as root; vendor firmware updates are available and users are urged to install the listed builds immediately, while no active exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
