HIGH 8.5 NVD
CVE-2026-16348
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands w
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.
Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
References
- https://www.tp-link.com/en/support/download/archer-be800/v1/#Firmware
- https://www.tp-link.com/us/support/download/archer-be800/v1/#Firmware
- https://www.tp-link.com/us/support/faq/5264/
This high severity vulnerability with a CVSS score of 8.5 was published on 2026-08-24 via NVD.
vulnfeed aggregates 11313 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.