Executive brief
TP-Link Archer BE450 and BE7200 routers are affected by a security flaw in their web management interface. An authorized administrator can bypass security restrictions to execute unauthorized system commands on the device. This could allow a user with management access to fully compromise the router, modify its configuration, or disrupt network operations.
Technical details
An authenticated command injection vulnerability exists in the web management interface of TP-Link Archer BE450 v1 and BE7200 v1 routers. The flaw stems from improper sanitization of input passed to backend system commands, which can be manipulated via the browser's developer console after successful authentication. An attacker with administrative privileges can exploit this to execute arbitrary commands with elevated privileges on the underlying operating system. This could lead to unauthorized service execution, configuration changes, or full device compromise. TP-Link has released firmware version 1.3.0 Build 20260416 to address these security issues.
Affected products
- TP-Link Archer BE450 v1
- TP-Link Archer BE7200 v1
Timeline
- 2026-04-16: patched: Firmware version 1.3.0 Build 20260416 released
- 2026-05-27: disclosed: CVE-2026-5509 published