Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78541— Command Injection in Parent Control of TP-Link Archer BE3600 v1

Quick assessment

Affected
TP-Link Systems Inc. Archer BE3600 v1
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TP-Link Archer BE3600 V1 的家长控制模块中存在一个存储型操作系统命令注入漏洞。具有管理权限的本地相邻攻击者可存储一个包含 Shell 元字符的恶意配置文件名称,该名称在每日云报告生成过程中会被不安全地处理,从而导致任意命令执行。 成功利用此漏洞可能使攻击者在受影响设备上执行命令,进而对设备的机密性、完整性和可用性造成潜在影响。

CVSS 8.5 · High EPSS 0.96% · P59
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78541

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Command Injection in Parent Control of TP-Link Archer BE3600 v1
Source: CVE Program / CVE List V5
Vulnerability Description
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Archer BE3600 v1 0 ~ 1.2.6 Build 20260617 -

II. Public POCs for CVE-2026-78541

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-78541

登录查看更多情报信息。

Vendor Advisories for CVE-2026-78541 (1)

Vendor Pages for CVE-2026-78541 (2)

Same Patch Batch · TP-Link Systems Inc. · 2026-08-24 · 4 CVEs total

CVE-2026-9254 8.7 HIGH Command Injection Vulnerability in Parent Control of Multiple TP-Link Archer Devices
CVE-2026-16348 8.5 HIGH Command Injection Vulnerability in VPN connection of Archer BE800
CVE-2026-15469 7.7 HIGH Hard-coded Mesh Group Private Key in TP-Link Deco XE75, XE5300, and WE10800

IV. Related Vulnerabilities

V. Comments for CVE-2026-78541

No comments yet


Leave a comment