Executive brief
TP-Link Archer routers include parental control functionality that filters internet access for specific devices. Due to improper input validation, an attacker on the local network can inject arbitrary commands that execute with root privileges, potentially compromising the router completely and intercepting all network traffic.
Technical details
An unauthenticated OS command injection vulnerability exists in the parental control functionality due to improper filtering and neutralization of special characters in certain parameters. The vulnerability is exploitable by a LAN-based attacker without authentication. Successful exploitation allows injection and execution of arbitrary commands with root privileges, leading to complete device compromise affecting confidentiality, integrity, and availability of the device and network traffic.
Affected products
- TP-Link Archer BE800 V1
- TP-Link Archer BE3600 V1
- TP-Link Archer AX75 V1
Timeline
- 2026-08-24: disclosed