Impact
An OS Command Injection flaw exists in the firmware of TP‑Link Archer BE230 routers running version 1.2 (vpn modules) and the OpenVPN component of the AXE75 v1. An adjacent authenticated attacker can submit malicious input that the device forwards to the operating system shell, enabling execution of arbitrary code. This results in full administrative control over the device, which severely compromises configuration integrity, network security and service availability.
Affected Systems
TP‑Link Systems Inc. sells the Archer BE230 and AXE75 routers. The vulnerability affects Archer BE230 firmware version 1.2 up to, but not including, 1.2.4 (Build 20251218 rel.70420) and Archer AXE75 firmware v1 up to, but not including, v1.5.6 (Build 20260623). No other versions are impacted.
Risk and Exploitability
With a CVSS score of 8.5 the flaw is considered high severity, yet the EPSS score of 0.01364 indicates that exploitation attempts are extremely rare at present. The attacker must be authenticated to the device and capable of sending crafted input, typically via a locally connected user. The absence from the KEV catalog indicates no known active exploitation. Still, the potential to gain complete administrative control warrants immediate mitigation.
OpenCVE Enrichment