CVE-2026-22226 is an authenticated operating system command injection vulnerability in the VPN server configuration module of TP-Link Archer BE230 v1.2 and Archer AX73 v2 routers. The flaw affects a distinct code path among multiple separately tracked command injection issues in these products. An authenticated administrator can reach the vulnerable functionality and supply input that is improperly neutralized before being incorporated into OS-level command execution. Successful exploitation can result in execution of arbitrary operating system commands on the device and escalation to full device administrative control.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone Python PoC repository for CVE-2026-22226. The repo contains one executable script (poc.py), a minimal README, license, and .gitignore. The script targets TP-Link Archer routers via the LuCI web interface and demonstrates an authenticated LAN-side stored blind OS command injection in the VPN client 'des' field. It first requests RSA key material from /login?form=keys, encrypts the supplied admin password with PKCS#1 v1.5 RSA, logs in through /login?form=login, and stores the returned stok token for subsequent authenticated requests. It then uploads a crafted OpenVPN configuration to /admin/vpn?form=open, inserts a malicious VPN client object through /admin/vpn?form=server with the description field set to a shell injection wrapper around the payload, and triggers vulnerable processing via /admin/vpn?form=ovpn using operation=read. The hardcoded payload is 'telnetd -l ash -p 1337', which attempts to expose a telnet shell on port 1337. Finally, the script removes the malicious VPN entry for cleanup. This is a real exploit PoC rather than a detector: it performs end-to-end exploitation with a basic hardcoded post-exploitation payload, making it operational but not heavily weaponized.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown (listed as a trending CVE affecting TP-Link Archer BE230; no technical details provided in the content).
Unknown (listed as a trending CVE affecting TP-Link Archer BE230; no technical details provided in the content).
Unknown (listed as a trending CVE affecting TP-Link Archer BE230; no technical details provided in the content).
Authenticated OS command injection vulnerability in TP-Link Archer BE230 v1.2 (within the disclosed CVE cluster) enabling arbitrary OS command execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.