Executive brief
TP-Link Archer BE230 and BE3600 routers contain an OS command injection vulnerability in the VPN module that allows an authenticated attacker on the adjacent network to execute arbitrary system commands. Successful exploitation grants an attacker full administrative control of the router, compromising network security, service availability, and the integrity of all network traffic passing through the device.
Technical details
An OS command injection vulnerability exists in the VPN module of affected TP-Link router firmware versions. The vulnerability is triggered through improper input validation in code that processes VPN configuration parameters. An authenticated attacker with network access to the router's management interface (adjacent network access) can inject arbitrary shell commands that are executed with root/administrative privileges. Exploitation results in remote code execution and complete device compromise. Patches are available: Archer BE230 v1.2 should be updated to 1.2.4 Build 20251218 rel.70420 or later; the advisory indicates similar vulnerabilities in other models are tracked separately under distinct CVE identifiers.
Affected products
- TP-Link Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420
- TP-Link Archer BE3600 v1
Timeline
- 2026-02-02: disclosed
- 2026-02-02: advisory