VYPR

Archer BE800

by TP-Link

CVEs (2)

  • CVE-2026-9254HigAug 24, 2026
    risk 0.57cvss epss

    An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary…

  • CVE-2026-16348HigAug 24, 2026
    risk 0.55cvss epss

    An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful exploitation may enable…