CVE-2026-9254Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges. Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 6 mentions (2026-08-25); latest day: 1
  • 9 total mentions across 3 days

Deep dive

Activity timeline9 mentions / 3d
02356Mentions · 2026-08-24: 2Mentions · 2026-08-25: 6Mentions · 2026-09-10: 1Patch / Workaround · 2026-08-25: 6Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 6Technical Details · 2026-09-10: 108-2408-2509-10
Signal classification2 categories
Patch
555.6%
Disclosure
444.4%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-242
Disclosure2
2026-08-256
Disclosure1Patch5
2026-09-101
Disclosure1
Full discourse9 posts
  • yousukezan@yousukezan
    Patch

    TP-LinkはArcherシリーズのルーター3製品に存在する深刻な脆弱性3件を修正した。最も重大なのは、認証なしでOSコマンドを実行できる「CVE-2026-9254」で、LAN内の攻撃者がroot権限を取得できる。 影響するのはArcher BE800 v1、Archer BE3600 v1、Archer AX75 v1。CVE-2026-9254はペアレンタルコントロール機能で特殊文字の処理が不十分なため、特定パラメータへ任意のシェルコマンドを注入できる。 CVE-2026-16348は、認証済み管理者がVPN接続を通じてコマンドを注入できる脆弱性。CVE-2026-78541は保存型のコマンドインジェクションで、管理者権限を持つ攻撃者が細工したプロファイル名を保存すると、日次のクラウドレポート生成時にコマンドが実行される。 TP-LinkはそれぞれArcher BE800 v1向けに1.4.2 Build 260708、BE3600 v1向けに1.2.6 Build 20260617、AX75 v1向けに1.1.6 Build 260716を公開した。記事によると、実際の攻撃での悪用は確認されていない。 https://securityonline.info/cve-2026-9254-unauthenticated-os-command-injection/

    Post summary

    TP‑Link released patches for three severe command‑injection CVEs affecting Archer routers, detailing the vulnerabilities and fix builds, but reports confirm no active exploitation has been observed.

    060311.8K
    16.0K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    TP-Link Archer BE800 v1, Archer BE3600 v1, Archer AX75 v1に無認証OSコマンドインジェクションの脆弱性。CVE-2026-9254はペアレンタルコントロールにおける不具合で、LANからroot権限で任意のコマンドを注入可能。修正あり。 https://securityonline.info/cve-2026-9254-unauthenticated-os-command-injection/

    Post summary

    The post announces a CP-2026-9254 unauthenticated OS command injection flaw in TP‑Link routers, notes that it allows root‑level command execution from LAN through a parental‑control defect, and indicates that a patch has been released.

    02051925
    7.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🚨 TP-Link Archer router'larda kritik komut enjeksiyonu açıkları! TP-Link'in Archer BE800 V1, BE3600 V1 ve AX75 V1 modellerinde 3 yüksek seviyeli güvenlik açığı tespit edildi. 🔴 CVE-2026-9254 özellikle dikkat çekiyor. Kimlik doğrulama gerektirmeyen açık, yerel ağdaki saldırganların router üzerinde root yetkisiyle işletim sistemi komutları çalıştırmasına olanak tanıyor. Diğer iki açık ise VPN ve ebeveyn denetimi özelliklerini etkiliyor. TP-Link, tüm etkilenen modeller için güvenlik güncellemelerini yayınladı. Kullanıcıların firmware sürümlerini kontrol ederek cihazlarını güncellemesi öneriliyor. Firmware güncellemeleri indirme sayfası: https://www.tp-link.com/tr/support/download/

    Post summary

    TP‑Link disclosed a critical command‑injection flaw (CVE‑2026‑9254) that lets unauthenticated local attackers run OS commands with root privileges, and has issued firmware updates that users should install.

    01042728
    2.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9254 An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering … https://www.cve.org/CVERecord?id=CVE-2026-9254

    Post summary

    The snippet announces CVE-2026-9254 as an unauthenticated OS command injection flaw affecting Archer BE800 V1, BE3600 V1, and AX75 V1 routers, citing improper filtering. No exploit code, PoC, or evidence of active exploitation is provided.

    00001993
    58.0K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【重要】TP-Link ArcherにCVSS 8.7、LAN内からroot権限でコマンド実行 https://www.cybernote.click/2026/09/01/tp-link-archer-cve-2026-9254-command-injection/ #IT #Security #cybersecurity

    Post summary

    The text announces CVE‑2026‑9254, a high‑severity vulnerability in TP‑Link Archer routers that allows root command execution from the LAN.

    0000044
    205 followersView on X
  • Kyssta@kysstalol
    Patch

    TP-Link Archer BE800, BE3600, AX75: unauthenticated OS command injection (CVE-2026-9254, CVSS 8.7) in parental control. Firmware updates out. Source: https://tp-link.com/us/support/faq/5264

    Post summary

    CVE-2026-9254 is an unauthenticated OS command injection affecting TP‑Link routers; firmware updates are now available to fix the vulnerability.

    0000033
    26 followersView on X
  • Kyssta@kysstalol
    Patch

    TP-Link Archer BE800, BE3600, and AX75 hit with unauthenticated OS command injection (CVE-2026-9254, CVSS 8.7) in the parental-control module. Firmware updates are out. Source: https://tp-link.com/us/support/faq/5264

    Post summary

    A newly disclosed unauthenticated OS command injection (CVE‑2026‑9254, CVSS 8.7) affects TP‑Link routers, and firmware updates have been released to remediate the issue.

    0000033
    26 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers. #TPLink #CyberSecurity #CVE20269254 #CommandInjection https://securityonline.info/cve-2026-9254-unauthenticated-os-command-injection/

    Post summary

    TP‑Link has released patches for multiple OS command injection vulnerabilities, including CVE‑2026‑9254, with no indication of active exploitation or a Proof of Concept.

    00000429
    12.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9254 An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering … https://www.cve.org/CVERecord?id=CVE-2026-9254 ----- Traducción: CVE-2026-9254 Exi… https://infoflow.cloud`

    Post summary

    The post is a disclosure alert about CVE-2026-9254, an unauthenticated OS command injection in Cisco Archer router parental control, with technical details but no PoC, exploit, patch, or active exploitation evidence.

    0000025
    102 followersView on X

Explore more