PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-0631 TP-Link Systems Inc. CVE debrief

An OS Command Injection vulnerability exists in TP-Link Archer BE230 v1.2 and OpenVPN of AXE75 v1. This allows an adjacent authenticated attacker to execute arbitrary code, potentially gaining full administrative control of the device. The vulnerability affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE75 v1 < 1.5.6 Build 20260623. Network administrators and security teams should be aware of this vulnerability and take steps to mitigate it. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. Although similar in nature, each instance is tracked under a unique CVE ID. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network security, and service availability.

Vendor
TP-Link Systems Inc.
Product
Archer BE230 v1.2
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-02
Original CVE updated
2026-07-31
Advisory published
2026-02-02
Advisory updated
2026-07-31

Who should care

Network administrators and security teams responsible for TP-Link Archer BE230 and AXE75 devices should be aware of this vulnerability and take steps to mitigate it. They should prioritize patching vulnerable devices to prevent potential code execution attacks. Additionally, they should restrict access to vulnerable devices to only trusted networks and users, monitor network activity for suspicious commands or behavior, and perform regular firmware updates and security audits. IT managers and cybersecurity professionals should also review their organization's exposure and implement compensating controls where necessary. This includes reviewing network configurations, ensuring proper segmentation, and implementing additional security measures to detect and prevent exploitation attempts. Furthermore, security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. They should also consider the operational impact of the vulnerability on their organization and plan accordingly. The vulnerability's severity and potential impact on the organization's security posture necessitate prompt attention and action from these stakeholders. They should also verify the affected scope and validate vendor guidance to ensure effective mitigation. By taking these steps, they can minimize the risk associated with this vulnerability and protect their organization's assets. The CVE record was published on 2026-02-02T18:16:13.620Z and has not been modified since then. The vulnerability's details and potential impact should be carefully reviewed by these stakeholders to ensure they are adequately prepared to address the issue. They should also consider the source-confidence limits and review context to ensure effective mitigation. The vulnerability affects multiple products and has significant implications for network security and service availability. Therefore, it is essential that these stakeholders take proactive measures to mitigate the vulnerability and prevent potential attacks. They should also monitor for any updates or changes to the CVE record and adjust their mitigation strategies accordingly. By doing so, they can ensure

Technical summary

The vulnerability is an OS Command Injection issue in TP-Link Archer BE230 v1.2 and OpenVPN of AXE75 v1. An adjacent authenticated attacker can exploit this to execute arbitrary code, potentially gaining full administrative control of the device. This CVE covers one of multiple distinct OS command injection issues identified across separate code paths. The affected products are Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE75 v1 < 1.5.6 Build 20260623.

Defensive priority

Administrators should prioritize patching vulnerable TP-Link Archer BE230 and AXE75 devices to prevent potential code execution attacks.

Recommended defensive actions

  • Apply patches for Archer BE230 v1.2 and Archer AXE75 v1 as per vendor advisories.
  • Restrict access to vulnerable devices to only trusted networks and users.
  • Monitor network activity for suspicious commands or behavior.
  • Perform regular firmware updates and security audits.
  • Review network configurations and ensure proper segmentation.
  • Implement additional security measures to detect and prevent exploitation attempts.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE details an OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and OpenVPN of AXE75 v1, allowing adjacent authenticated attackers to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-02-02T18:16:13.620Z and has not been modified since then.