Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-9254 — TP-Link Archer BE800 V1 — Parental Control LAN RCE | Kitploit
أدوات/GitHubGitHub/slagzz/cve-2026-9254
IoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingHardware & IoT Security
GitHubslagzz/cve-2026-9254

CVE-2026-9254

TP-Link Archer BE800 V1 — Parental Control LAN RCE

عرض المستودع
9منذ 21 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

TP-Link Archer BE800 V1 — Parental Control LAN RCE

CVE: CVE-2026-9254
CVSS: 8.7 (High)
Auth required: None
Network position: LAN only
Found on version 1.3.2 Build 20251015 rel.10659(5553)

Summary

The parental control blocking endpoint (/cgi-bin/luci/blocking?form=vercode) is reachable from the LAN without admin credentials. The url parameter is passed to a shell command via fork_exec(string.format("%s %s %s", BINARY, owner_id, url)) after a character deny-list check. The deny-list does not include the newline character (0x0a), allowing a newline-terminated command to be appended. Commands execute as root.

A secondary information-disclosure bug on the same endpoint allows reading the current vercode without credentials, eliminating the only piece of information that cannot be observed from the captive portal redirect URL.


demo

Blog Writeup

https://uploadsecurity.com/Blog/CVE-2026-16348_research.html


Researcher

[email protected]

تنزيل الأداة