PatchSiren

TP-Link Systems Inc. CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH TP-Link Systems Inc. CVE published 2026-02-02

CVE-2026-22221

CVE-2026-22221 is an OS Command Injection vulnerability affecting TP-Link Archer BE230 v1.2 and BE3600 v1. An authenticated attacker with adjacent access can exploit this issue to execute arbitrary code, potentially gaining full administrative control of the device. This could result in severe compromise of configuration integrity, network security, and service availability.

HIGH TP-Link Systems Inc. CVE published 2026-02-02

CVE-2026-0631

An OS Command Injection vulnerability exists in TP-Link Archer BE230 v1.2 and OpenVPN of AXE75 v1. This allows an adjacent authenticated attacker to execute arbitrary code, potentially gaining full administrative control of the device. The vulnerability affects Archer BE230 v1.2 < 1.2.4 Build 20251218 rel.70420 and Archer AXE75 v1 < 1.5.6 Build 20260623. Network administrators and security teams should be [truncated]