CVE-2026-16348: Command Injection Vulnerability in VPN connection of Archer BE800
Published Aug 24, 2026
·Updated
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.
Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
Affected Software
1 affected component
TP-Link Archer BE800 V1=V1
Event History
Aug 24, 2026
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need before exploiting this issue?
The attacker must already have administrative access to the TP-Link Archer BE800 V1 and be able to supply input through a VPN connection.
2
What privileges would successful exploitation provide?
Successful command injection allows execution of arbitrary system commands with root privileges. This may support persistent backdoors, credential theft, LAN reconnaissance, and attacks against devices connected to the router.