THREAT OPS › Threat News › [NVD] CVE-2026-22223 (HIGH 8.0) — An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent
authenticated
attacker
execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in seve
[NVD] CVE-2026-22223 (HIGH 8.0) — An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in seve
CVE-2026-22223 CVSS: 8.0 HIGH Published: 2026-02-02T18:16:15.007
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent
authenticated
attacker
execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severe compromise of configuration integrity, network secu
Indicators of compromise
- CVE-2026-22223cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-22223