Impact
A stored OS command injection flaw resides in the parent‑control module of the TP‑Link Archer BE3600 v1 router. An attacker who has gained administrative or adjacent access can embed shell metacharacters in a profile name that is later stored and processed during the router’s cloud‑reporting routine. When the report is generated, the unsanitized profile name is passed to the operating system shell, enabling arbitrary commands to be executed on the device. This capability can compromise the router’s confidentiality, integrity, and availability.
Affected Systems
The flaw affects only the TP‑Link Archer BE3600 v1 models. No other TP‑Link products or firmware revisions are known to be impacted. The specific version check is currently limited to the v1 hardware and its embedded firmware.
Risk and Exploitability
The CVSS base score of 8.5 classifies the issue as high severity, and the lack of an EPSS rating or KEV listing suggests no widely known public exploits yet, although the flaw is straightforward to abuse once administrative access is achieved. Based on the description, the attacker must have administrative or adjacent access to the device, meaning the attack vector is local or via a compromised adjacent device. If these conditions are met, the flaw permits arbitrary command execution. No publicly disclosed exploits are available at the time of this analysis, and the vulnerability is not listed in CISA’s KEV catalog, but the CVSS score of 8.5 indicates a high likelihood of impact.
OpenCVE Enrichment