Stored OS command injection in TP-Link Archer BE3600 parent control

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-78541?

CVE-2026-78541 is a vulnerability classified as Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), affecting Archer BE3600 v1 (affected versions: < 1.2.6 Build 20260617). This vulnerability is rated High, with a CVSS score of 8.5. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenticated adjacent attacker with administrative access may store a crafted profile name containing shell metacharacters, which is later processed unsafely during daily cloud report generation and may result in arbitrary command execution. Successful exploitation may allow command execution on the affected device with potential impact to device confidentiality, integrity, and availability.

Affected products and scope

  • TP-Link Systems Inc. Archer BE3600 V1, parent-control module: the normalized record identifies firmware versions less than 1.2.6 Build 20260617 as affected; the structured range begins at 0 and has default status unaffected.
  • A later regional TP-Link advisory also identifies Archer BE3600 V1.20 as affected and names 1.2.6 Build 20260617 as the fixed firmware. V1.20 is not present in the initial normalized affected list, so it should be inventoried and checked separately rather than treated as unaffected.

Technical details

TP-Link Archer BE3600 has a CWE-78 flaw in the parent-control module, where an administrator-controlled profile name is stored and later processed during daily cloud report generation. A profile name containing shell metacharacters may not be neutralized correctly, causing stored data to be interpreted as part of an OS command rather than as text. Exploitation requires authenticated administrative access and an adjacent network position; the record indicates that no user interaction is required after the value is stored. The documented flow is that an attacker stores a crafted profile name, after which the cloud-report task processes the value and may execute arbitrary commands on the device. The available evidence does not identify the exact command or shell, execution context, privilege of the report-generation process, or whether that process runs as root.

Exploitability

The attacker must be authenticated, have administrative privileges, and have adjacent network access to the device. The record describes low attack complexity and no user interaction; the malicious value is stored first and later processed during daily cloud report generation. The supplied record does not identify a public exploit, while the associated CISA ADP assessment records Exploitation: none and Automatable: no within that assessment's scope. This does not establish that future exploitation is impossible.

Technical impact

The technical outcome may be arbitrary command execution on Archer BE3600 through stored profile data processed by the parent-control function. The documented direct impacts are to the confidentiality, integrity, and availability of the device; the actual level of control depends on the privileges of the report-processing task, which have not been disclosed. The attacker must have authenticated administrative access and an adjacent network position, so the flaw is not an unconditional path from every network location. If those prerequisites are met, command execution could enable router behavior changes, service disruption, or access to data the router can read; these are possible consequences, not a confirmed breach.

Business impact

Successful exploitation may allow an attacker to execute commands on the router, affecting the device's confidentiality, integrity, and availability. Depending on the affected process's privileges and the data accessible to the router, possible consequences include configuration changes, service disruption, or unauthorized access to information handled by the device. The administrative-access requirement limits exploitation by attackers without those privileges, but it makes protection of administrative accounts and adjacent management paths especially important. The available evidence does not identify a particular breach, victim, or downstream system.

Remediation

  1. Upgrade Archer BE3600 V1 and V1.20 to the fixed firmware 1.2.6 Build 20260617 from the official TP-Link website for the device's purchase location. TP-Link identifies this release as the fix for these branches.
  2. Verify the hardware branch before upgrading. TP-Link warns that installing the wrong firmware can damage the device and affect its warranty.
  3. Follow the vendor's upgrade guidance: use a wired connection where practical, stop Internet applications or disconnect the Internet line from the device during the upgrade when appropriate, and do not power off the router during the process.
  4. If an upgrade cannot be completed immediately, restrict administrative management to trusted adjacent networks and reduce unnecessary access to administrative accounts. This is an interim precaution, not a vendor-confirmed workaround.
  5. The consulted sources do not provide a specific workaround for this flaw. Do not treat changing profile names or disabling an individual feature as a fix unless TP-Link confirms that approach.

Detection

  1. Inventory all TP-Link Archer BE3600 devices, including hardware branch, current firmware, and use of the parent-control module; compare firmware with the fixed release stated in remediation.
  2. Review parent-control profile names for unexpected shell metacharacters, unexplained changes, or values inconsistent with local naming conventions. This is a precautionary check based on the affected input, not a vendor-confirmed IOC.
  3. Review router telemetry and daily cloud-report activity for report-generation failures, configuration changes, command-execution activity, or unusual outbound connections around the report task. These are general monitoring precautions, not specific log events confirmed by the sources.
  4. Correlate administrative authentication records with adjacent-network management access around the time profiles were changed, where such records are available.
  5. The absence of suspicious profile values or unusual log activity does not prove that a device is safe because the available sources do not define a complete indicator set.
Sources (19)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan