CVE-2026-16348
Command Injection Vulnerability in VPN connection of Archer BE800
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.ย Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
| CWE | CWE-78 |
| Vendor | tp-link systems inc. |
| Product | archer be800 v1 |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. archer be800 v1
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. archer be800 v1 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / Archer BE800 v1
0 < 1.4.2 Build 260708
References
Credits
Sean Lagan, UploadSecurity