TP-Link has patched three severe vulnerabilities in its Archer router series. The most critical issue is an unauthenticated OS command injection flaw tracked as CVE-2026-9254. Therefore, users must update their devices immediately to block potential intrusions.
- Product: TP-Link Systems Inc. (3 products)
- Vulnerabilities: 3 flaws (CVE-2026-9254, CVE-2026-16348, CVE-2026-78541)
- Highest severity: 8.7 (High · CVSSv4)
- Worst impact: Command Injection in Parent Control of Multiple TP-Link Archer Devices
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.4.2 Build 260708, 1.2.6 Build 20260617, 1.1.6 Build 260716 now
| CVE | CVSS | Fixed in | Status |
|---|
Why These Vulnerabilities Matter
These security flaws expose home and enterprise networks to total compromise. Specifically, attackers can gain full root access to the router. They can then steal credentials or deploy persistent backdoors. According to the vendor advisory, “Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.” Industry estimates suggest thousands of these routers are active globally. However, experts have not confirmed any active exploitation in the wild.
How the Attacks Work
CVE-2026-9254
This unauthenticated OS command injection flaw occurs within the parental control module. The router fails to filter special characters properly. Consequently, an attacker on the local network can inject shell commands directly into specific parameters. As the advisory notes, “A LAN-based attacker can inject arbitrary commands and execute them with root privileges.”
CVE-2026-16348 and CVE-2026-78541
Additionally, CVE-2026-16348 allows an authenticated administrator to inject commands through a VPN connection. Furthermore, CVE-2026-78541 is a stored command injection vulnerability. An attacker with administrative access saves malformed profile names. The router then executes these characters during daily cloud report generation.
Affected Versions and Mitigation Steps
These flaws impact Archer BE800 v1, Archer BE3600 v1, and Archer AX75 v1 hardware. To secure your network, you must install the patched firmware releases. TP-Link released versions 1.4.2 Build 260708, 1.2.6 Build 20260617, and 1.1.6 Build 260716 respectively. You can find detailed instructions and download the files from the official TP-Link security advisory. Always verify your specific hardware version before applying updates.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!