CVE-2026-9254

HIGHCVSS 8.7/10EPSS 2.35%

Last modified

CVE-2026-9254 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.. EPSS estimates a 2.35% chance of exploitation in the next 30 days.

Description

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
TP-Link Systems Inc.Archer BE800 V1< 1.4.2 Build 260708
TP-Link Systems Inc.Archer BE3600 V1< 1.2.6 Build 20260617
TP-Link Systems Inc.Archer AX75 V1< 1.1.6 Build 260716

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-9254?
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
How severe is CVE-2026-9254?
CVE-2026-9254 has a CVSS score of 8.7/10 (HIGH severity). The EPSS model estimates a 2.35% probability of exploitation in the next 30 days.
How do I fix CVE-2026-9254?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-9254?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST