
A PoC/exploit has been discovered for vulnerability CVE-2026-16348 Vendor: TP-Link Systems Inc. Product: Archer BE800 v1 Description: An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection. Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices. Link: https://github.com/slagzz/cve-2026-16348 #dbugs_vuln
Post summary
An authenticated command‑injection PoC and exploit for CVE‑2026‑16348 on TP‑Link Archer BE800 V1 has been released, enabling root‑level command execution via VPN, but no evidence of active exploitation or patches is shared.



