PatchSiren cyber security CVE debrief
CVE-2026-5509 TP-Link Systems Inc. CVE debrief
An authenticated command injection vulnerability in TP-Link Archer BE450 v1 and BE7200 v1 routers allows administrators to execute arbitrary system commands through the web management interface. The vulnerability stems from insufficient input sanitization when crafted input is passed to backend system commands. Successful exploitation grants elevated privileges, enabling unauthorized service startup, system configuration modification, or full device compromise. The CVSS 4.0 vector indicates attack vector from adjacent network (AV:A), low attack complexity (AC:L), high privileges required (PR:H), and high impact across confidentiality, integrity, and availability (VC:H/VI:H/VA:H). The vulnerability is classified under CWE-20 (Improper Input Validation). As of publication, the CVE status is 'Awaiting Analysis' per NVD. No known exploitation in ransomware campaigns has been documented, and the vulnerability has not been added to CISA KEV.
- Vendor
- TP-Link Systems Inc.
- Product
- Archer BE7200 V1
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-27
- Original CVE updated
- 2026-06-02
- Advisory published
- 2026-05-27
- Advisory updated
- 2026-06-02
Who should care
Network administrators managing TP-Link Archer BE450 or BE7200 deployments; security teams responsible for edge network infrastructure; SOHO and residential users with administrative access to these router models
Technical summary
The vulnerability exists in the web management interface of TP-Link Archer BE450 v1 and BE7200 v1 routers. After authentication, an attacker with administrative privileges can supply crafted input through the browser's developer console that is passed to backend system commands without adequate sanitization. This results in arbitrary command execution with elevated privileges. The attack requires adjacent network access and high privileges, but low attack complexity. Impact is rated high for confidentiality, integrity, and availability of the device.
Defensive priority
HIGH
Recommended defensive actions
- Apply firmware updates from TP-Link for Archer BE450 and BE7200 routers when available
- Restrict administrative access to the web management interface to trusted internal networks only
- Implement network segmentation to isolate router management interfaces from untrusted networks
- Monitor for unauthorized configuration changes or unexpected service startups on affected devices
- Review and rotate administrative credentials if compromise is suspected
- Disable remote web management access if not strictly required for operations
Evidence notes
Vulnerability description sourced from official CVE record and NVD entry. Product identification (TP-Link Archer BE450 v1, BE7200 v1) derived from CVE description and reference links to TP-Link support pages. CVSS 4.0 vector and CWE-20 classification from NVD source metadata. Vendor attribution supported by reference domain evidence pointing to TP-Link. CVE status 'Awaiting Analysis' confirmed from NVD source metadata.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5509 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5509
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5509 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5509
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/en/support/download/archer-be450/
f23511db-6c3e-4e32-a477-6aa17d310630
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/jp/support/download/archer-be450/
f23511db-6c3e-4e32-a477-6aa17d310630
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/jp/support/download/archer-be7200/
f23511db-6c3e-4e32-a477-6aa17d310630
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/us/support/faq/5102/
f23511db-6c3e-4e32-a477-6aa17d310630
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.