Impact
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1. The flaw allows an attacker on the local network to inject malicious commands that are executed with root privileges. Successful exploitation can lead to total device compromise, jeopardizing confidentiality, integrity, and availability of the device and surrounding network traffic.
Affected Systems
The vulnerability affects TP‑Link Systems Inc. routers Archer AX75 V1, Archer BE3600 V1, and Archer BE800 V1. No other versions are confirmed to be impacted, and the issue is linked to the parental control feature in firmware versions V1 of these models.
Risk and Exploitability
With a CVSS score of 8.7, this risk is high. The EPSS score is 2%, but the lack of authentication requirement and root‑level command execution indicates a significant exploitation likelihood. Because the attacker needs only local LAN access, the attack surface is large within an untrusted network. The issue is not listed in CISA KEV, yet the severity and potential for widespread compromise warrant immediate attention.
OpenCVE Enrichment