Impact
An OS Command Injection flaw exists in the VPN modules of TP‑Link Archer BE230 firmware 1.2 and the Archer BE3600 firmware 1.0, permitting an authenticated attacker with adjacent or local network access to execute arbitrary shell commands. Successful exploitation would grant the attacker full administrative control of the device, allowing compromise of configuration integrity, disruption of network services, and potential disclosure of sensitive information. This vulnerability is classified as CWE‑78, representing the improper handling of untrusted input that is passed directly to the operating system.
Affected Systems
The flaw affects TP‑Link Systems Inc. Archer BE230 routers running firmware version 1.2 and any subsequent 1.2.x release up to but not including 1.2.4 (Build 20251218 rel.70420), as well as Archer BE3600 routers with firmware version 1.0. Devices with older or unpatched firmware in these ranges are vulnerable.
Risk and Exploitability
The CVSS base score of 8.5 marks this issue as highly severe. The EPSS score is 1%, suggesting a low current exploitation rate, and the vulnerability is not listed in CISA’s KEV catalog. Attack requires local or adjacent authenticated access, and while no public exploit has been reported, the presence of a command injection vector means any compromised account can elevate privileges or trigger arbitrary code execution.
OpenCVE Enrichment