TP-Link has released a critical security advisory addressing multiple authenticated command injection vulnerabilities affecting its popular Archer BE230 Wi-Fi 7 router (v1.2).
The flaws, collectively tracked under several CVE identifiers, could allow an authenticated attacker to execute arbitrary system commands and gain full administrative control over the device.
The issues were responsibly disclosed by independent researchers jro, caprinuxx, and sunshinefactory, and officially acknowledged by TP-Link in an advisory updated on February 2, 2026.
Vulnerability Overview
Security researchers discovered multiple OS command injection flaws in different modules of the Archer BE230 firmware, specifically version 1.2 (builds before 1.2.4 Build 20251218 rel.70420).
Each vulnerability arises from insufficient input validation within administrative interfaces, where user-supplied parameters are executed without proper sanitization.
These issues affect a range of web and VPN-related components:
- Web Management Modules (CVE-2026-0630, CVE-2026-22222)
- VPN Modules and Services (CVE-2026-0631, CVE-2026-22221, CVE-2026-22223, CVE-2026-22225, CVE-2026-22226)
- Cloud and Configuration Functions (CVE-2026-22224, CVE-2026-22227, CVE-2026-22229)
Although exploitation requires administrative authentication, a threat actor who has acquired credentials through phishing, brute forcing, or prior compromise could use these flaws to execute arbitrary shell commands on the router’s operating system.
The attack would allow modification of configurations, interception of network traffic, or complete disruption of service availability.
The severity scores range between 8.5 and 8.6 (High) on the CVSS v4.0 scale, emphasizing the potential impact on confidentiality, integrity, and availability of the device and the connected network.
| CVE ID | Affected Component | CVSS v4.0 Score | Severity | Access Vector |
|---|---|---|---|---|
| CVE-2026-0630 | Web Module | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-0631 | VPN Module | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22221 | VPN Module | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22222 | Web Module | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22223 | VPN Module | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22224 | Cloud Communication | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22225 | VPN Connection Service | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22226 | VPN Config Module | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22227 | Config Backup Restore | 8.5 | High | Adjacent (AV:A) |
| CVE-2026-22229 | Crafted Config File Import | 8.6 | High | Network (AV:N) |
A successful exploit could let attackers gain full administrative privileges, manipulate firmware settings, and redirect traffic, compromising both device and data integrity.
enterprise or shared home environments, this could expose sensitive data or open a foothold for deeper network intrusion.
Mitigation: TP-Link strongly advises users to immediately upgrade to firmware v1.2.4 Build 20251218 rel.70420 or later. Updated firmware is available through the official TP-Link support portals.
As a best practice, administrators should also enforce strong router passwords, disable remote management if not needed, and regularly review firmware updates to reduce attack exposure.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.