TP-Link Archer BE3600 V1 的家长控制模块中存在一个存储型操作系统命令注入漏洞。具有管理权限的本地相邻攻击者可存储一个包含 Shell 元字符的恶意配置文件名称,该名称在每日云报告生成过程中会被不安全地处理,从而导致任意命令执行。 成功利用此漏洞可能使攻击者在受影响设备上执行命令,进而对设备的机密性、完整性和可用性造成潜在影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Archer BE3600 v1 | 0 ~ 1.2.6 Build 20260617 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9254 | 8.7 HIGH | Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices |
| CVE-2026-16348 | 8.5 HIGH | Command Injection Vulnerability in VPN connection of Archer BE800 |
| CVE-2026-15469 | 7.7 HIGH | Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800 |
No comments yet