Archer BE3600
by TP-Link
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-9254 | Hig | 0.57 | — | 0.03 | Aug 24, 2026 | An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary… | ||
| CVE-2026-78541 | Hig | 0.55 | — | 0.02 | Aug 24, 2026 | A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during… | ||
| CVE-2026-22223 | Hig | 0.52 | 8.0 | 0.01 | Feb 2, 2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in… | ||
| CVE-2026-22221 | Hig | 0.52 | 8.0 | 0.01 | Feb 2, 2026 | An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in… | ||
| CVE-2026-0631 | Hig | 0.52 | 8.0 | 0.02 | Feb 2, 2026 | An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full… |
- risk 0.57cvss —epss 0.03
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary…
- risk 0.55cvss —epss 0.02
A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during…
- risk 0.52cvss 8.0epss 0.01
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in…
- risk 0.52cvss 8.0epss 0.01
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in…
- risk 0.52cvss 8.0epss 0.02
An OS Command Injection vulnerability exists in the Surfshark VPN login functionality in TP-Link Archer BE230 v1.2, BE3600v1 and AXE75 v1, allowing an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full…