VYPR

Archer BE3600

by TP-Link

CVEs (2)

  • CVE-2026-9254HigAug 24, 2026
    risk 0.57cvss epss

    An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary…

  • CVE-2026-78541HigAug 24, 2026
    risk 0.55cvss epss

    A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during…