CVE-2026-5509 Details
Description
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s developer console by supplying a crafted input that is passed to backend system commands without adequate sanitization. Successful exploitation enables execution of arbitrary commands with elevated privileges on the device, which may allow the attacker to start unauthorized services, modify system configuration, or otherwise fully compromise the router’s operating environment.
A command injection vulnerability has been identified in the TP-Link Archer BE450 v1 and BE7200 v1 routers. This vulnerability allows authenticated administrators to execute arbitrary system commands via the web management interface. Exploitation involves sending crafted inputs through the browser's developer console, which are then passed to backend system commands without proper sanitization. Successful exploitation could lead to unauthorized command execution with elevated privileges, potentially allowing attackers to modify system configurations, start unauthorized services, or fully compromise the router's operating environment.
Users are advised to update to the latest firmware version. The patched version for both the Archer BE450 and BE7200 is 1.3.0 Build 20260416. Instructions for downloading the firmware are available on the TP-Link support pages for each router model.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU95687008/ | TPLink | |
| https://www.tp-link.com/en/support/download/archer-be450/#Firmware | TPLink | Product |
| https://www.tp-link.com/jp/support/download/archer-be450/#Firmware | TPLink | Product |
| https://www.tp-link.com/jp/support/download/archer-be7200/#Firmware | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5102/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-20 | Improper Input Validation | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link archer be450 firmware | < 1.3.0 |
CPE
Remediation
| |
| tp-link archer be450 | 1.0 |
CPE
Remediation
| |
| tp-link archer be7200 firmware | < 1.3.0 |
CPE
Remediation
| |
| tp-link archer be7200 | 1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | TPLink |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | TPLink |