{"id":"CVE-2026-78541","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-78541","summary":"A stored OS\ncommand injection vulnerability exists in the parent-control module of TP-Link\nArcher BE3600 V1. An authenticated adjacent attacker with administrative access\nmay store…","details":"A stored OS\ncommand injection vulnerability exists in the parent-control module of TP-Link\nArcher BE3600 V1. An authenticated adjacent attacker with administrative access\nmay store a crafted profile name containing shell metacharacters, which is\nlater processed unsafely during daily cloud report generation and may result in\narbitrary command execution.\n\n\n\n\n\nSuccessful\nexploitation may allow command execution on the affected device with potential\nimpact to device confidentiality, integrity, and availability.","published":"2026-08-24T19:17:04.553","modified":"2026-08-24T19:17:04.553","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/archer-be3600/v1/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/archer-be3600/v1.26/#Firmware"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5264/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T19:17:04.553"}}