CVE-2026-16348Disclosure

MEDIUMCVSS 8.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-24); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-24: 2Mentions · 2026-08-25: 2PoC Mentioned / Linked · 2026-08-25: 1Exploit Tool / Code · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 208-2408-25
Signal classification4 categories
Disclosure
125.0%
General
125.0%
Patch
125.0%
PoC
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure1General1
2026-08-252
Patch1PoC1
Full discourse4 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-16348 Vendor: TP-Link Systems Inc. Product: Archer BE800 v1 Description: An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices. Link: https://github.com/slagzz/cve-2026-16348 #dbugs_vuln

    Post summary

    An authenticated command‑injection PoC and exploit for CVE‑2026‑16348 on TP‑Link Archer BE800 V1 has been released, enabling root‑level command execution via VPN, but no evidence of active exploitation or patches is shared.

    01042457
    3.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers. #TPLink #CyberSecurity #CVE20269254 #CommandInjection https://securityonline.info/cve-2026-9254-unauthenticated-os-command-injection/

    Post summary

    The post announces that TP‑Link has released a patch for an unauthenticated OS command injection flaw (CVE‑2026‑9254) on Archer routers, indicating a vendor remediation effort.

    00000429
    12.9K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-16348 An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with ro… https://www.cve.org/CVERecord?id=CVE-2026-16348 ----- Traducción: CVE-2026-16348 Una… https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-16348, a command‑injection flaw in TP‑Link Archer BE800 V1 that permits admin users to run arbitrary commands, without evidence of a PoC, active exploitation, or a patch.

    0000030
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-16348 An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with ro… https://www.cve.org/CVERecord?id=CVE-2026-16348

    Post summary

    An authenticated command injection vulnerability was disclosed in TP‑Link Archer BE800 V1, enabling privileged users to execute arbitrary system commands.

    00000903
    58.0K followersView on X

Explore more