Impact
An authenticated command injection flaw in the Archer BE800 V1 router allows an attacker with administrative credentials to insert shell metacharacters into VPN control traffic and execute arbitrary root‑level commands on the device. The injected commands can persist as backdoors, harvest credentials, conduct internal network scans, and facilitate subsequent attacks against devices on the private LAN. This ability directly compromises confidentiality, integrity, and availability of the router and its connected infrastructure.
Affected Systems
The vulnerability affects TP‑Link Systems Inc. Archer BE800 routers running firmware version v1. No other vendor or product variants are noted by the CNA. Users of this device model should verify their firmware version and apply any available updates from TP‑Link to mitigate the issue.
Risk and Exploitability
The CVSS score is 8.5, indicating a high severity of exploitability and impact. The EPSS score is not available, so the current probability of exploitation is unclear. The issue is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is remote injection through the VPN management interface, requiring an authenticated session. Once exploited, attackers can achieve full root control of the router, enabling persistent compromise and lateral movement within the local network.
OpenCVE Enrichment