Junglewise Threat Intelligence

CVE-2026-22226: TP-Link Archer command injection in VPN server configuration

CVE-2026-22226 · Severity: high · CVSS 7.2 · Published 2026-02-02

Executive brief

A security vulnerability has been identified in TP-Link Archer BE230 and AX73 routers, which are used to provide home and small office internet connectivity. An attacker who has already gained administrative access to the router's management interface can execute unauthorized commands through the VPN configuration module. This could allow the attacker to take full control of the device, potentially leading to network eavesdropping, service disruptions, or further attacks on connected devices.

Technical details

An OS command injection vulnerability (CWE-78) exists in the VPN server configuration module of TP-Link Archer BE230 (v1.2) and Archer AX73 (v2) routers. The flaw resides in specific code paths within the VPN module that fail to properly neutralize special elements used in OS commands. An attacker must first authenticate as an administrator to reach the vulnerable component. Once authenticated, the attacker can inject malicious commands to gain full administrative control (root access) over the underlying operating system. This vulnerability is one of several distinct command injection issues identified in these products, each tracked under separate IDs. Patches are available in firmware versions 1.2.4 Build 20251218 for the BE230 and 1.3.1 Build 20260430 for the AX73.

Affected products

  • TP-Link Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420
  • TP-Link Archer AX73 v2 < 1.3.1 Build 20260430

Timeline

  • 2026-02-02: disclosed
  • 2026-02-02: advisory

References

Related threats