CVE Explorer
CVE-2026-5509
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interface. After successfully authenticating to the admin interface, an attacker can leverage the browser’s developer console by supplying a crafted input that is passed to backend system commands without adequate sanitization.
Successful exploitation enables execution of arbitrary commands with elevated
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"Archer BE7200 V1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.3.0 Build 20260416","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"Archer BE450 v1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.3.0 Build 20260416","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"Archer BE7200 V1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.3.0 Build 20260416","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"Archer BE450 v1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.3.0 Build 20260416","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"tags":["third-party-advisory"],"url":"https://jvn.jp/en/vu/JVNVU95687008/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/references/4
{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/archer-be450/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/references/0
{"tags":["patch"],"url":"https://www.tp-link.com/jp/support/download/archer-be450/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/references/1
{"tags":["patch"],"url":"https://www.tp-link.com/jp/support/download/archer-be7200/#Firmware"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/references/2
{"tags":["patch","vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/5102/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:328e2bdaf110115f06eac3d786ea71bef0df8a9bce35e29918e8620af1c368b3 · sha256:a3304bca490e0c8f… · /containers/cna/references/3
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.