TP-Link releases critical firmware updates after command injection vulnerabilities in Archer routers

TP-Link has issued urgent firmware updates for three Archer router models following the discovery of multiple command injection flaws that could allow local network attackers to compromise device security and gain root privileges.

TP-Link has issued firmware updates for three Archer routers after disclosure of multiple command injection flaws that could let an attacker run operating system commands with root privileges. According to the company’s security advisory, the affected devices are the Archer BE800 V1, Archer BE3600 V1 and Archer AX75 V1, with the most serious issue requiring only local network access rather than existing credentials.

The highest-risk flaw, tracked as CVE-2026-9254, affects the parental control function across all three models. TP-Link said the problem stems from inadequate handling of special characters in certain inputs, allowing a person on the same local network to supply crafted data and trigger command execution as root. The advisory rates the issue 8.7 under CVSS v4.0, reflecting adjacent-network exposure, low complexity and no need for user interaction.

Two further vulnerabilities were also patched. TP-Link said CVE-2026-16348 affects the Archer BE800 V1 and can be abused by an administrator through the VPN connection feature to inject shell commands with root privileges. CVE-2026-78541 affects the Archer BE3600 V1 and involves stored command injection in the parental control module, where a malicious profile name may execute later during daily cloud report generation. That delayed behaviour could make compromise harder to detect and investigate.

TP-Link has published fixed firmware for each model: Archer BE800 V1 should be updated to 1.4.2 Build 260708, Archer BE3600 V1 to 1.2.6 Build 20260617, and Archer AX75 V1 to 1.1.6 Build 260716. The company advised owners to install the updates promptly, limit router administration access to trusted local hosts, review parental control and VPN settings for unusual changes, and change administrative credentials if compromise is suspected.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.