CVE-2026-9254 is an unauthenticated operating system command injection vulnerability in the parental control functionality of TP-Link Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers. The flaw is caused by improper filtering and neutralization of special characters in certain input parameters, allowing attacker-controlled data to be incorporated into OS command execution. An attacker on the local network can exploit the vulnerable parental control interface without authentication and cause arbitrary commands to be executed with root privileges. The issue affects the router control plane and can lead to full compromise of the affected device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit for CVE-2026-9254 affecting the TP-Link Archer BE800 V1 parental control functionality. The repository contains 3 files: a single Python exploit script, a README describing the vulnerability and affected version, and a license. The exploit is not part of a larger framework. The main file, CVE-2026-9254.py, implements an interactive LAN-side RCE exploit against the router’s /cgi-bin/luci/blocking?form=vercode endpoint. It first abuses an information disclosure issue to read the current vercode without authentication using the token and MAC values obtained from the captive portal redirect URL. It then sends a POST request where the url parameter contains a newline injection payload. That payload causes the router to execute attacker-controlled shell commands as root. Operationally, the exploit uses a two-stage design. Stage 1 injects commands that make the router fetch a shell script from the attacker’s temporary HTTP server using wget and save it as /tmp/s.sh. Stage 2 executes that script, which runs an operator-supplied command and pipes the output to nc, sending results back to the attacker’s TCP listener. This avoids the target’s deny-list restrictions while providing an interactive shell-like loop. Capabilities include unauthenticated vercode retrieval, arbitrary command execution as root, hosting a transient HTTP payload server, and receiving command output over a callback socket. The exploit requires LAN adjacency and a reachable attacker host on the same network, but no admin credentials. Based on the included payloading and interactive command loop, this is an operational exploit rather than a simple detection script or bare proof of concept.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated OS command injection vulnerability in the parental-control function of TP-Link Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 routers that can allow a local-network attacker to execute arbitrary commands as root.
An unauthenticated OS command injection vulnerability in the parental control functionality of TP-Link Archer BE800 V1, BE3600 V1, and AX75 V1 that allows a LAN-based attacker to execute arbitrary commands with root privileges, potentially leading to full device compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.