TP-Link: Four High-Severity Command Injection & Crypto Key Flaws Hit Archer, Deco Routers
TP-Link addresses four high-severity vulnerabilities, including command injection and hard-coded keys, across Archer and Deco router lines.

Key findings
- Four high-severity vulnerabilities disclosed on August 24, 2026, affect TP-Link routers and mesh systems.
- Three command injection flaws (CVE-2026-78541, CVE-2026-9254, CVE-2026-16348) allow root command execution.
- CVE-2026-9254 affects Archer BE800 V1, BE3600 V1, and AX75 V1, enabling unauthenticated attacks.
- CVE-2026-15469 involves a hard-coded cryptographic key in Deco mesh systems.
- TP-Link has released firmware updates for all affected models.
On August 24, 2026, TP-Link addressed a batch of four high-severity vulnerabilities impacting several of its router models. The disclosures, spanning a two-hour window, highlight significant security weaknesses in command injection and cryptographic key management across the Archer and Deco product lines. These vulnerabilities could allow attackers to gain root privileges, execute arbitrary commands, and potentially compromise entire networks.
Three of the disclosed vulnerabilities, CVE-2026-78541, CVE-2026-9254, and CVE-2026-16348, are related to OS command injection. CVE-2026-78541 affects the parent-control module of the TP-Link Archer BE3600 V1, allowing authenticated adjacent attackers to inject shell metacharacters that are later processed unsafely. Similarly, CVE-2026-9254 impacts the parental control functionality in Archer BE800 V1, BE3600 V1, and AX75 V1, enabling unauthenticated LAN-based attackers to inject arbitrary commands with root privileges due to improper character filtering. CVE-2026-16348, found in the TP-Link Archer BE800 V1, permits authenticated attackers with administrative access to execute arbitrary system commands with root privileges via a VPN connection by injecting shell metacharacters. Successful exploitation of these command injection flaws could lead to persistent backdoors and credential theft. Cyber Security News
The fourth vulnerability, CVE-2026-15469, stems from the use of a hard-coded cryptographic key in the mesh functionality of Deco XE75 v3, XE5300 v3.6, and WE10800 v3.6. A shared RSA-512 mesh group private key is present in the affected firmware, which is used for node authentication. An attacker obtaining the firmware could leverage this hard-coded key to compromise the mesh network's integrity.
TP-Link has released firmware updates to address all four vulnerabilities. Users of the affected Archer BE3600 V1, Archer BE800 V1, Archer AX75 V1, Deco XE75 v3, XE5300 v3.6, and WE10800 v3.6 models are strongly urged to update their devices to the latest firmware version as soon as possible to mitigate the risks associated with these high-severity flaws.
The coordinated disclosure of these vulnerabilities underscores the importance of timely patching for network infrastructure devices. Users should remain vigilant and ensure their TP-Link routers and mesh systems are running the most current firmware to protect against potential exploitation, which could lead to significant network compromise and data breaches.