Junglewise Threat Intelligence

CVE-2026-22223: TP-Link Archer BE230 and BE3600 OS command injection in VPN module

CVE-2026-22223 · Severity: high · CVSS 8 · Published 2026-02-02

Technologies: TP-Link Archer Be230, TP-Link Archer Be230 Firmware, TP-Link Archer BE3600. Vendors: TP-Link.

Executive brief

TP-Link Archer BE230 and BE3600 routers contain an OS command injection vulnerability in the VPN module that allows an authenticated attacker on the adjacent network to execute arbitrary system commands. Successful exploitation grants an attacker full administrative control of the router, compromising network security, service availability, and the integrity of all network traffic passing through the device.

Technical details

An OS command injection vulnerability exists in the VPN module of affected TP-Link router firmware versions. The vulnerability is triggered through improper input validation in code that processes VPN configuration parameters. An authenticated attacker with network access to the router's management interface (adjacent network access) can inject arbitrary shell commands that are executed with root/administrative privileges. Exploitation results in remote code execution and complete device compromise. Patches are available: Archer BE230 v1.2 should be updated to 1.2.4 Build 20251218 rel.70420 or later; the advisory indicates similar vulnerabilities in other models are tracked separately under distinct CVE identifiers.

Affected products

  • TP-Link Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420
  • TP-Link Archer BE3600 v1

Timeline

  • 2026-02-02: disclosed
  • 2026-02-02: advisory

References

Related threats