CVE-2026-22226Disclosure(tp-link / archer_be230)

MEDIUMCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch tp-link archer_be230 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AX73 v2 < 1.3.1 Build 20260430.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • archer_be230
  • archer_be230_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-02); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
archer_be230archer_be230_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-02: 2Mentions · 2026-07-23: 1Mentions · 2026-07-24: 1PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-07-24: 1Exploit Tool / Code · 2026-07-23: 1Exploit Tool / Code · 2026-07-24: 1Patch / Workaround · 2026-07-24: 1Technical Details · 2026-02-02: 2Technical Details · 2026-07-23: 1Technical Details · 2026-07-24: 102-0207-2307-24
Signal classification2 categories
Disclosure
250.0%
PoC
250.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-022
Disclosure2
2026-07-231
PoC1
2026-07-241
PoC1
Full discourse4 posts
  • ThreatWire@ThreatWire_
    PoC

    🚨 A public PoC has been released for CVE-2026-22226 affecting TP-Link Archer BE230 v1.2 and Archer AX73 v2. The flaw allows authenticated command injection, potentially leading to full device compromise. Patched in the latest firmware. 🔗 https://github.com/lucasvanhaaren/cve-2026-22226 #TPLink

    Post summary

    A public PoC and GitHub link were released for CVE-2026-22226, a command injection flaw in TP‑Link devices, with the issue already patched in the latest firmware.

    00115111.7K
    1.4K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-22226 PT ID: PT-2026-5690 Vendor: TP-Link Systems Inc. Product: Archer BE230 v1.2 Description: A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. This issue affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AX73 v2 < 1.3.1 Build 20260430. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-5690 • https://github.com/lucasvanhaaren/cve-2026-22226 #dbugs_vuln

    Post summary

    CVE‑2026‑22226 is a command injection vulnerability in TP‑Link Archer router firmware; a Proof‑of‑Concept/exploit has been released and is publicly available via a GitHub repository.

    02054692
    3.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22226 A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on the TP-Link Archer BE230 v1.2. Successfu… https://www.cve.org/CVERecord?id=CVE-2026-22226

    Post summary

    The text announces a command injection flaw in TP‑Link Archer BE230 v1.2’s VPN server module after admin authentication, without providing exploit code, active attack evidence, or a patch.

    00000183
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22226 Command Injection in TP-Link Archer BE230 VPN Configuration Modul... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22226 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-22226, a command‑injection flaw in the TP‑Link Archer BE230 VPN configuration module, and directs readers to a vulnerability database page, but does not provide exploit code, patch details, or evidence of active exploitation.

    0000072
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linkarcher_be2301.20--
OStp-linkarcher_be230_firmware---

Explore more