logo

CVE-2026-9254: Unauthenticated OS Command Injection Hits TP-Link Archer

ID: aba1afc2-0db6-5ab7-823c-042f551fdb1e

STIX ID: report--aba1afc2-0db6-5ab7-823c-042f551fdb1e

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Do Son

...
...

TP-Link released patches for three severe command-injection vulnerabilities affecting Archer BE800 v1, BE3600 v1, and AX75 v1 (CVE-2026-9254, CVE-2026-16348, CVE-2026-78541). The most critical is an unauthenticated OS command injection in the parental control module that can allow local attackers to execute commands as root; vendor firmware updates are available and users are urged to install the listed builds immediately, while no active exploitation has been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.