Junglewise Threat Intelligence

CVE-2026-9254: TP-Link Archer OS command injection in parental control

CVE-2026-9254 · Severity: info · Published 2026-08-24

Technologies: TP-Link Archer BE3600. Vendors: TP-Link.

Executive brief

TP-Link Archer routers include parental control functionality that filters internet access for specific devices. Due to improper input validation, an attacker on the local network can inject arbitrary commands that execute with root privileges, potentially compromising the router completely and intercepting all network traffic.

Technical details

An unauthenticated OS command injection vulnerability exists in the parental control functionality due to improper filtering and neutralization of special characters in certain parameters. The vulnerability is exploitable by a LAN-based attacker without authentication. Successful exploitation allows injection and execution of arbitrary commands with root privileges, leading to complete device compromise affecting confidentiality, integrity, and availability of the device and network traffic.

Affected products

  • TP-Link Archer BE800 V1
  • TP-Link Archer BE3600 V1
  • TP-Link Archer AX75 V1

Timeline

  • 2026-08-24: disclosed

References

Related threats