TP-Link Archer Series Command Injection Vulnerability in Wireless Control and Modem Management CLI Commands

Vulnerability

A command injection vulnerability has been identified in TP-Link Archer NX200, NX210, NX500, and NX600 routers. This vulnerability arises from improper input handling in administrative command-line interface (CLI) commands related to wireless control and modem management. An authenticated attacker with administrative privileges can exploit this vulnerability to execute arbitrary commands on the operating system, potentially affecting the device's functionality and security.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device's operating system, which could lead to unauthorized changes, data access, or disruption of device functionality.

Remediation

Users are advised to update to the latest firmware version. Firmware updates can be downloaded from the TP-Link support website for each specific model.

Added: Mar 23, 2026, 6:25 PM
Updated: Mar 23, 2026, 6:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.0
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.