Executive brief
The TP-Link Archer BE800 V1 Wi-Fi 7 router contains a command injection vulnerability in its VPN functionality that allows administrators with valid login credentials to execute arbitrary system commands with root privileges. An attacker exploiting this can install backdoors, steal credentials, scan the local network, and launch attacks against connected devices, potentially compromising the security of all networks and devices relying on the router.
Technical details
The vulnerability is an authenticated command injection flaw in the VPN connection handling code of the Archer BE800 V1. The vulnerable component fails to properly sanitize shell metacharacters in VPN-related parameters before passing them to system commands. An attacker with administrative access can inject shell metacharacters (such as backticks, pipes, or semicolons) through VPN configuration fields to break out of intended command boundaries and execute arbitrary commands with root privileges. Exploitation requires valid admin credentials and is not known to have been exploited in the wild as of publication.
Affected products
- TP-Link Archer BE800 V1
Timeline
- 2026-08-24: disclosed
- other: CVE-2026-16348 assigned