Executive brief
TP-Link Archer wireless routers (BE230 and BE3600 models) contain an OS command injection vulnerability in VPN-related code that allows an authenticated user on the network to execute arbitrary commands with administrative privileges. An attacker exploiting this flaw could take complete control of the router, compromise network security settings, intercept or redirect user traffic, and disrupt internet service for all devices connected to it.
Technical details
An OS command injection vulnerability exists in the VPN module code path of TP-Link Archer BE230 v1.2 and BE3600 v1 routers, allowing authenticated adjacent network attackers to inject and execute arbitrary operating system commands. The vulnerability requires network proximity and prior authentication but not necessarily administrative credentials. Successful exploitation grants full administrative control of the device, enabling attackers to modify router configuration, install malicious code, and compromise network operations. A patch is available for Archer BE230 (version 1.2.4 Build 20251218 rel.70420 or later); patch status for BE3600 should be verified with TP-Link.
Affected products
- TP-Link Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420
- TP-Link Archer BE3600 v1
Timeline
- 2026-02-02: disclosed
- 2026: other: Patch available for Archer BE230 version 1.2.4 Build 20251218 rel.70420