Junglewise Threat Intelligence

CVE-2026-78541: TP-Link Archer BE3600 stored OS command injection in parental control

CVE-2026-78541 · Severity: info · CVSS 8.8 · Published 2026-08-24

Technologies: TP-Link Archer BE3600. Vendors: TP-Link.

Executive brief

The TP-Link Archer BE3600 router's parental control feature contains a vulnerability that allows an authenticated administrator to inject malicious shell commands via a crafted profile name. When the router generates daily cloud reports, these stored commands are executed with device privileges, potentially compromising the router's security and enabling full system takeover.

Technical details

A stored OS command injection vulnerability exists in the parent-control module where user-supplied profile names containing shell metacharacters are not properly sanitized before being processed during automated cloud report generation. The vulnerability requires administrative access and operates on the local network (adjacent attack vector). Successful exploitation allows arbitrary command execution on the device with full compromise of confidentiality, integrity, and availability. The vulnerable code path is triggered asynchronously during the daily cloud report process, making it a time-delayed but reliable exploitation vector.

Affected products

  • TP-Link Archer BE3600 V1

Timeline

  • 2026-08-24: disclosed

References

Related threats