Description
A stored OS
command injection vulnerability exists in the parent-control module of TP-Link
Archer BE3600 V1. An authenticated adjacent attacker with administrative access
may store a crafted profile name containing shell metacharacters, which is
later processed unsafely during daily cloud report generation and may result in
arbitrary command execution.





Successful
exploitation may allow command execution on the affected device with potential
impact to device confidentiality, integrity, and availability.
Published: 2026-08-24
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Command Execution
Action: Immediate Patch
AI Analysis

Impact

A stored OS command injection flaw resides in the parent‑control module of the TP‑Link Archer BE3600 v1 router. An attacker who has gained administrative or adjacent access can embed shell metacharacters in a profile name that is later stored and processed during the router’s cloud‑reporting routine. When the report is generated, the unsanitized profile name is passed to the operating system shell, enabling arbitrary commands to be executed on the device. This capability can compromise the router’s confidentiality, integrity, and availability.

Affected Systems

The flaw affects only the TP‑Link Archer BE3600 v1 models. No other TP‑Link products or firmware revisions are known to be impacted. The specific version check is currently limited to the v1 hardware and its embedded firmware.

Risk and Exploitability

The CVSS base score of 8.5 classifies the issue as high severity, and the lack of an EPSS rating or KEV listing suggests no widely known public exploits yet, although the flaw is straightforward to abuse once administrative access is achieved. Based on the description, the attacker must have administrative or adjacent access to the device, meaning the attack vector is local or via a compromised adjacent device. If these conditions are met, the flaw permits arbitrary command execution. No publicly disclosed exploits are available at the time of this analysis, and the vulnerability is not listed in CISA’s KEV catalog, but the CVSS score of 8.5 indicates a high likelihood of impact.

Generated by OpenCVE AI on August 24, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by TP‑Link (e.g., firmware 1.26) to remove the vulnerable parent‑control module.
  • If an immediate firmware update cannot be applied, disable all remote management features and restrict access to the router’s administrative interface to trusted local users only.
  • Avoid storing profile names that contain shell metacharacters or perform input validation on profile names to strip or encode such characters before storing them.

Generated by OpenCVE AI on August 24, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Be3600 V1
Vendors & Products Tp-link
Tp-link archer Be3600 V1

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.
Title Command Injection in Parent Control of TP-Link Archer BE3600 v1
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

Tp-link Archer Be3600 V1
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-25T03:56:57.446Z

Reserved: 2026-08-24T17:49:50.653Z

Link: CVE-2026-78541

cve-icon Vulnrichment

Updated: 2026-08-24T19:14:53.080Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T19:17:04.553

Modified: 2026-08-28T19:02:53.760

Link: CVE-2026-78541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:09:56Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')