TP-Link Vulnerabilities Let Hackers Take Full Control of Devices
TP-Link has reported several critical authenticated command injection vulnerabilities in the Archer BE230 v1.2 Wi-Fi router. These vulnerabilities allow attackers with administrative access to execute arbitrary commands and gain full control over…
TP-Link has reported several critical authenticated command injection vulnerabilities in the Archer BE230 v1.2 Wi-Fi router. These vulnerabilities allow attackers with administrative access to execute arbitrary commands and gain full control over affected devices.
Security researchers identified nine distinct vulnerabilities, each tracked under separate CVE identifiers. The vulnerabilities affect various components of the router's firmware, including web interfaces, VPN modules, cloud communication systems, and configuration management functions.
The vulnerabilities result from insufficient input validation in multiple firmware components. Exploiting these flaws allows attackers to inject malicious operating system commands through authenticated interfaces, bypassing standard security controls.
Eight of the nine vulnerabilities require adjacent network access with high privileges. However, one flaw (CVE-2026-22229) can be exploited remotely by importing specially crafted configuration files.
Successful exploitation provides attackers with full administrative control over the router, potentially compromising configuration integrity, network security, and service availability. The vulnerabilities could also enable persistent backdoor installation, traffic interception, network pivoting, and complete infrastructure compromise in both enterprise and home network environments.
CVE ID Affected Component CVSS v4.0 Attack Vector Privileges Required
CVE-2026-0630 Web Modules 8.5 Adjacent Network High
CVE-2026-22222 Web Modules 8.5 Adjacent Network High
TP-Link has reported several critical authenticated command injection vulnerabilities in the Archer BE230 v1.2 Wi-Fi router.
CVE-2026-0631 VPN Modules 8.5 Adjacent Network High
CVE-2026-22221 VPN Modules 8.5 Adjacent Network High
CVE-2026-22223 VPN Modules 8.5 Adjacent Network High
CVE-2026-22224 Cloud Communication 8.5 Adjacent Network High
CVE-2026-22225 VPN Connection Service 8.5 Adjacent Network High
CVE-2026-22226 VPN Server Configuration 8.5 Adjacent Network High
CVE-2026-22227 Configuration Backup 8.5 Adjacent Network High
CVE-2026-22229 Configuration File Import 8.6 Network High
All nine CVE identifiers affect Archer BE230 v1.2 firmware versions before 1.2.4 Build 20251218. The vulnerabilities have CVSS v4.0 severity scores between 8.5 and 8.6, classified as High severity. CVE-2026-22229 presents the highest risk with a score of 8.6 due to its network-accessible attack vector, while the remaining eight CVEs score 8.5 with adjacent network access requirements.
The affected components include web administration modules, VPN infrastructure, cloud communication services, and configuration backup systems.
TP-Link released firmware version 1.2.4 Build 20251218 rel.70420 on Mon, Feb 2, 2026, addressing all nine vulnerabilities. Users are advised to download and install the patched firmware from official TP-Link regional support portals.
Unpatched devices remain vulnerable, and TP-Link assumes no responsibility for consequences resulting from failure to apply security updates.
Based on reporting by GBHackers.
