CVE-2026-16348
EUVD-2026-6500724.08.2026, 18:16
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection. Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
Awaiting analysis
This vulnerability is currently awaiting analysis.