Tp Link · Archer Be230 · CVE-2026-22226
**Name of the Vulnerable Software and Affected Versions**
TP-Link Archer BE230 versions prior to 1.2.4 Build 20251218 rel.70420
**Description**
A command injection issue exists following administrator authentication within the VPN server configuration module. Successful exploitation could grant an attacker complete administrative control over the device, potentially compromising configuration integrity, network security, and service availability. The issue affects multiple code paths, each tracked under a unique identifier. The vulnerability is triggered in the VPN server configuration module.
**Recommendations**
Update to version 1.2.4 Build 20251218 rel.70420 or later.