CVE-2026-78541Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-24); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-24: 2Mentions · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 108-2408-25
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure2
2026-08-251
Patch1
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers. #TPLink #CyberSecurity #CVE20269254 #CommandInjection https://securityonline.info/cve-2026-9254-unauthenticated-os-command-injection/

    Post summary

    TP‑Link has released a patch for CVE‑2026‑9254, an unauthenticated OS command injection vulnerability, while also noting other risks such as CVE‑2026‑16348 and CVE‑2026‑78541.

    00000429
    12.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-78541 A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative ac… https://www.cve.org/CVERecord?id=CVE-2026-78541 ----- Traducción: CVE-2026-78541 Una… https://infoflow.cloud`

    Post summary

    The text announces CVE-2026-78541 as a stored OS command injection in TP‑Link Archer BE3600 V1’s parent‑control module, referencing its CVE record but offering no PoC, exploit, patch, or evidence of active exploitation.

    0000026
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-78541 A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative ac… https://www.cve.org/CVERecord?id=CVE-2026-78541

    Post summary

    The snippet announces a disclosed CVE-2026-78541, noting a stored OS command injection in TP‑Link Archer BE3600 V1 that requires authenticated administrative access; no PoC, exploit code, active exploitation, or patch details are provided.

    00000682
    58.0K followersView on X

Explore more