Impact
An OS Command Injection vulnerability in the VPN modules of the TP‑Link Archer BE230 v1.2 and BE3600 v1 allows an adjacent authenticated attacker to execute arbitrary shell commands. Successful exploitation can grant full administrative control of the device, compromising configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths in the firmware.
Affected Systems
TP‑Link Archer BE230 routers running firmware v1.20 and versions earlier than 1.2.4 (Build 20251218 rel.70420) and TP‑Link Archer BE3600 v1 routers are affected. The affected product is the Archer BE230 v1.2 as listed by TP‑Link System Inc.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating a high severity rating. The EPSS score is 2%, indicating a very low likelihood of active exploitation at present, and the issue is not catalogued in CISA’s KEV. Exploitation requires authenticated access, and the attack vector is inferred to be the VPN interface, so privileged local or network access is needed to leverage the flaw. Once executed, an attacker can gain unrestricted command execution.
OpenCVE Enrichment