VYPR

Archer BE3600

by TP-Link

CVEs (5)

  • CVE-2026-9254HigAug 24, 2026
    risk 0.57cvss —epss 0.03

    An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary…

  • CVE-2026-78541HigAug 24, 2026
    risk 0.55cvss —epss 0.02

    A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during…

  • CVE-2026-22223HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in…

  • CVE-2026-22221HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in…

  • CVE-2026-0631HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full…