Executive brief
A security vulnerability exists in the VPN modules of certain TP-Link Archer routers, which are devices used to manage home and small office internet connections. An attacker who is already connected to the local network could exploit this flaw to take full administrative control of the router. This could allow them to monitor network traffic, change security settings, or disable internet access entirely.
Technical details
An OS command injection vulnerability exists within the VPN modules of the TP-Link Archer BE230 v1.2 and the OpenVPN component of the Archer AXE75 v1. The flaw is caused by improper neutralization of special elements used in OS commands (CWE-78) across specific code paths. An adjacent attacker with low-level authentication can exploit this to execute arbitrary system commands. Successful exploitation grants the attacker full administrative access to the device, compromising configuration integrity and service availability. Patches are available in firmware versions 1.2.4 Build 20251218 (BE230) and 1.5.6 Build 20260623 (AXE75).
Affected products
- TP-Link Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420
- TP-Link Archer AXE75 v1 < 1.5.6 Build 20260623
Timeline
- 2026-02-02: advisory: Initial NVD publication date
- 2025-12-18: patched: Patch released for Archer BE230
- 2026-06-23: patched: Patch released for Archer AXE75
References
- https://www.tp-link.com/en/support/download/archer-axe75/v1/
- https://www.tp-link.com/en/support/download/archer-be230/v1.20/
- https://www.tp-link.com/sg/support/download/archer-be230/v1.20/
- https://www.tp-link.com/us/support/download/archer-axe75/v1/
- https://www.tp-link.com/us/support/download/archer-be230/v1.20/
- https://www.tp-link.com/us/support/faq/4935/