Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-9254 — TP-Link Archer BE800 V1 — Parental Control LAN RCE | Kitploit
Outils/GitHubGitHub/slagzz/cve-2026-9254
IoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingHardware & IoT Security
GitHubslagzz/cve-2026-9254

CVE-2026-9254

TP-Link Archer BE800 V1 — Parental Control LAN RCE

Voir le dépôt
9il y a 20 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

TP-Link Archer BE800 V1 — Parental Control LAN RCE

CVE: CVE-2026-9254
CVSS: 8.7 (High)
Auth required: None
Network position: LAN only
Found on version 1.3.2 Build 20251015 rel.10659(5553)

Summary

The parental control blocking endpoint (/cgi-bin/luci/blocking?form=vercode) is reachable from the LAN without admin credentials. The url parameter is passed to a shell command via fork_exec(string.format("%s %s %s", BINARY, owner_id, url)) after a character deny-list check. The deny-list does not include the newline character (0x0a), allowing a newline-terminated command to be appended. Commands execute as root.

A secondary information-disclosure bug on the same endpoint allows reading the current vercode without credentials, eliminating the only piece of information that cannot be observed from the captive portal redirect URL.


demo

Blog Writeup

https://uploadsecurity.com/Blog/CVE-2026-16348_research.html


Researcher

[email protected]

Télécharger l’outil