Command Injection Vulnerability on TP-Link Archer BE230 v1.2
A flaw in the TP-Link Archer BE230 router allows an authenticated admin to execute arbitrary commands on the device through the backup restoration feature. An attacker who gains admin access can take complete control of the router, compromising its security and network operations.
Command injection vulnerability in the configuration backup restoration function of TP-Link Archer BE230 v1.2, exploitable post-authentication via unsanitized input in backup processing. Successful exploitation grants arbitrary OS command execution with administrative privileges, enabling full device compromise, configuration manipulation, and network disruption. Affects versions prior to 1.2.4 Build 20251218 rel.70420.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →