CVE-2026-9254: Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.
Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be on the local network (LAN). No authentication is required.
What access does successful exploitation provide?
The attacker can inject and execute arbitrary operating-system commands with root privileges, which can lead to complete compromise of the device and affect device and network-traffic confidentiality, integrity, and availability.
Which devices are identified as affected?
The affected products are TP-Link Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1.