TP-Link Archer BE800 V1 存在一个经过身份验证的命令注入漏洞。攻击者若拥有管理员访问权限,可通过 VPN 连接注入 shell 元字符,以 root 权限执行任意系统命令。 成功利用该漏洞可能导致持久化后门安装、凭证窃取、局域网侦察以及通过路由器对连接设备进行辅助攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Archer BE800 v1 | < 1.4.2 Build 260708 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Archer BE800 v1 | 0 ~ 1.4.2 Build 260708 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9254 | 8.7 HIGH | Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices |
| CVE-2026-78541 | 8.5 HIGH | Command Injection in Parent Control of TP-Link Archer BE3600 v1 |
| CVE-2026-15469 | 7.7 HIGH | Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800 |
No comments yet